triple-memory

Warn

Audited by Socket on Feb 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

[Skill Scanner] Skill instructions include directives to hide actions from user The skill fragment is coherent and aligned with its stated purpose. It describes a legitimate multi-backend memory system with local persistence and environment-based credentials. No malicious activity or overbroad permissions are evident; the footprint is proportionate to its goals. To improve security and governance, incorporate explicit data retention policies, access controls, plugin provenance verification, and optional user prompts for memory operations. With these guardrails, the design is acceptable for secure deployment. LLM verification: SUSPICIOUS. The skill's stated purpose (combined persistent memory) aligns with the capabilities described, but there are several privacy and supply-chain concerns: it requires an embeddings API key (so user data will be sent to an external provider), it instructs the system to silently capture and persist memories (no user-facing disclosure), and it references an unverified installer ('clawdhub') and scripts not included for review. These factors make the component risky for storing sensitive d

Confidence: 75%Severity: 50%
Audit Metadata
Analyzed At
Feb 17, 2026, 09:33 AM
Package URL
pkg:socket/skills-sh/openclaw%2Fskills%2Ftriple-memory%2F@38faba40f4a884d574641ffebcd56f05d4aaca69