distill-memory

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The Distill Memory skill is conceptually coherent with its purpose of capturing high-value insights and persisting them via the nmem CLI. However, there are notable security and data-flow considerations: optional remote synchronization could leak memory content if not secured; credentials (apiKey) stored in config.json pose a risk if not properly protected; documentation lacks explicit data-scope and security controls for remote calls. Overall, the footprint is benign for a memory-management helper but warrants mitigations around credential handling, documented data flows, and secure transport for any remote API interactions.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 02:13 AM
Package URL
pkg:socket/skills-sh/nowledge-co%2Fcommunity%2Fdistill-memory%2F@dd517a351cdeeda61020ebe76c62da2e47d2aae6