persistent-memory

Fail

Audited by Socket on Feb 28, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
references/adapters/claude-code.md

This README outlines a local persistent-memory feature that reads/writes markdown files under ~/.persistent-memory and notes the agent can execute commands. The document itself contains no explicit malware or malicious code, but describes behaviors (automatic persistence, command execution, plaintext storage in ~) that, if implemented without safeguards, present moderate security risk: disclosure of secrets, accidental exfiltration via backups/sync, and potential for arbitrary command execution. Treat as a high-priority security design review: add explicit user consent, encryption, access controls, command execution restrictions, and sensitive-data detection before adopting.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 28, 2026, 12:49 PM
Package URL
pkg:socket/skills-sh/nangongwentian-fe%2Fagent-skills%2Fpersistent-memory%2F@e40a53c5cdd0c0351fe70e6aec07ea486c4ecdb8