rlm-curator

Fail

Audited by Socket on Mar 9, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The rlm-curator skill presents a coherent, purpose-aligned architecture for maintaining a semantic ledger with controlled, concurrency-safe access to a local cache. Its footprint—local Python scripts, explicit cache read/write flows, and avoidance of raw bash edits to critical files—appears proportionate to its stated purpose. While the setup relies on local services (Ollama server and agent swarms) and includes external dependencies in a controlled manner, there are no obvious credential exposures or external data exfiltration paths present in the provided description. Minor concerns include platform-specific locking behavior and dependency governance, which should be validated in deployment, but the overall risk appears manageable and aligned with its knowledge-curation objective.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 9, 2026, 06:57 PM
Package URL
pkg:socket/skills-sh/richfrem%2Fagent-plugins-skills%2Frlm-curator%2F@39ec4a9f38009776b3295d2c8039b8c07c6b48ba