Shell command execution detected (child_process).
- Code
- suspicious.dangerous_exec
- Location
- merged-src.js:16446
Security audit
Security checks across malware telemetry and agentic risk
This looks like a real memory skill, but it needs Review because it can automatically record and reuse conversations while the submitted install package is incomplete and its access scope is broader than disclosed.
Review before installing. Use it only if you want an automatic long-term memory system that may record conversations, index them, and inject recalled content into future prompts. Verify the real install source, keep cloud/provider credentials disabled unless intended, and confirm you can inspect, delete, export, and stop stored memories.
65/65 vendors flagged this skill as clean.
Detected: suspicious.dangerous_exec, suspicious.env_credential_access, suspicious.exposed_secret_literal (+1 more)