hindsight-docs

Warn

Audited by Socket on Sep 17, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
references/developer/mcp-server.md

No malware is evident because the supplied content is descriptive Markdown with no executable behavior. It documents a potentially high-impact MCP API that is open by default and includes cross-bank access, configuration changes, and destructive operations. Deployments should enable authentication, restrict network exposure, verify bank-level authorization, and limit enabled tools according to least privilege.

Confidence: 99%Severity: 62%
AnomalyLOW
references/sdks/integrations/claude-code.md

The fragment documents a legitimate memory and knowledge plugin, not an apparent malware payload. Its main security concern is intentional collection and transmission of conversation transcripts, tool results, and selected files to a configurable Hindsight service, with invisible recall injection and persistent storage. Review endpoint trust, access controls, retention, redaction, file-ingestion validation, bank isolation, and pin embedVersion rather than using latest. The absence of implementation code prevents verification of credential handling and path restrictions.

Confidence: 94%Severity: 62%
Audit Metadata
Analyzed At
Sep 17, 2026, 03:00 AM
Package URL
pkg:socket/skills-sh/vectorize-io%2Fhindsight%2Fhindsight-docs%2F@3484b48ed079d215308653b15473de87cb4a6170d42a455c08996c0158c6a722
Security Audit — socket — hindsight-docs