supermemory
Warn
Audited by Socket on Mar 21, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The core purpose is coherent with a memory API skill, and SuperMemory appears to be a real same-org service, but the skill includes a hardcoded-looking API key and routes all operations through unseen local shell scripts. The missing script contents make credential handling and actual network destinations unverifiable, and the examples normalize uploading sensitive data such as API keys to a third-party memory store.
Confidence: 87%Severity: 72%
Audit Metadata