File appears to expose a hardcoded API secret or token.
- Code
- suspicious.exposed_secret_literal
- Location
- skills/memory-config/SKILL.md:197
- Evidence
api_key = "[REDACTED]"
Security audit
Security checks across malware telemetry and agentic risk
This appears to be a real memory plugin, but it enables automatic conversation capture, recall injection, and sensitive hook permissions by default, so it belongs in Review before installation.
Install only if you want this plugin to retain and reuse conversation history across sessions. Before enabling it, review whether automatic capture and auto recall should be disabled, where .memsearch memory files are stored, how you will delete retained memories, and whether conversation-access and prompt-injection permissions are acceptable for your environment.
SkillSpector was not run because this plugin release contains no bundled skills.
64/64 vendors flagged this plugin as clean.
Detected: suspicious.exposed_secret_literal
api_key = "[REDACTED]"