Memrok
Security checks across malware telemetry and agentic risk
Overview
The skill's requirements and behavior match its stated purpose (local graph-based memory curation); it can read session transcripts and optional workspace Markdown and may call configured remote models — these behaviors are documented and opt-in.
This plugin is internally coherent for local-first, judged memory curation. Key things to consider before installing: (1) bootstrap (scanning workspace Markdown) is opt-in — keep it disabled unless you want broad file ingestion; (2) if you configure a remote scribe provider/model, session transcripts and selected file contents will be sent to that provider — prefer local models if privacy is a concern; (3) the plugin stores sensitive data in ~/.memrok/memrok.db — secure and back it up appropriately or change dbPath; (4) review the bundled system/reflection prompts (in dist/) before enabling remote providers to ensure they don't include behavior you dislike; (5) consider turning off reflective scribe or evalEvents if you want minimal exfiltration surface. If you want higher assurance, review the repo source (provided) and run the local inspection scripts (dry-run) the SKILL.md documents before enabling persistence or remote providers.
SkillSpector
SkillSpector findings are pending for this release.
VirusTotal
No VirusTotal findings
