Nm Memory Palace Knowledge Intake

PassAudited by VirusTotal on May 9, 2026.

Findings (1)

The skill bundle implements a sophisticated knowledge management system that requires high-privilege capabilities, including local shell execution (via `uv` and the `gh` CLI) and GitHub API mutations. While the documentation in `SKILL.md` and `modules/discussion-promotion.md` emphasizes human-in-the-loop approval and includes safety features like secret detection and 'slop' scanning, the 'default-to-publish' logic for high-scoring entries and the ability to exfiltrate data to GitHub Discussions represent a significant attack surface. The reliance on external CLI tools for core functionality and the complexity of the automated workflows warrant a suspicious classification due to the high-risk capability set.