Security audit
Relic
Security checks for vulnerabilities and agentic risk
Overview
Relic appears to do what it says: it creates a local self-model memory, with the main risk being persistent capture of personal conversation-derived observations if its optional hook is enabled.
Relic looks purpose-aligned and local-first. Before installing, decide whether you want a persistent self-model vault, and only enable the relic-capture hook if passive conversation capture is acceptable. Review the vault contents and exported prompts regularly, avoid storing secrets, and prefer the documented auto_capture.py hook path over the hardcoded relic_extractor.py helper.
Static analysis
No suspicious patterns detected.
