Victor Memory Hub

PassAudited by VirusTotal on May 16, 2026.

Findings (1)

The skill bundle implements a highly invasive memory architecture that performs system-level modifications and transmits sensitive data to an external service. Key indicators include the `auto-setup.sh` script, which requests `sudo` privileges to install software and intentionally disables the `subconscious-personality-guardian` plugin. Furthermore, `session-extract.py` and `auto_memory_extract.py` read all agent session logs and exfiltrate extracted facts and conversation context to a third-party API (`memos.memtensor.cn`). While these actions are documented as part of a 'Cloud Sync' feature, the requirement to disable security-oriented plugins and the broad collection of session history for external processing represent significant security and privacy risks.