supermemory

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core purpose is coherent with a memory API skill, and SuperMemory appears to be a real same-org service, but the skill includes a hardcoded-looking API key and routes all operations through unseen local shell scripts. The missing script contents make credential handling and actual network destinations unverifiable, and the examples normalize uploading sensitive data such as API keys to a third-party memory store.

Confidence: 87%Severity: 72%
Audit Metadata
Analyzed At
Mar 21, 2026, 01:02 PM
Package URL
pkg:socket/skills-sh/sundial-org%2Fawesome-openclaw-skills%2Fsupermemory%2F@0833c2872f0f24787edb1966ce8e4ae4403e6c8c