cm
Enhances AI coding agents with procedural memory and cross-agent learning, improving task efficiency and knowledge retention.
Install this skill
or
61/100
Security score
The cm skill was audited on Feb 28, 2026 and we found 9 security issues across 2 threat categories, including 1 high-severity. Review the findings below before installing.
Categories Tested
Security Issues
high line 799
Piping content to bash shell
SourceSKILL.md
| 799 | | bash -s -- --easy-mode --verify |
low line 70
Access to hidden dotfiles in home directory
SourceSKILL.md
| 70 | "source_path": "~/.claude/sessions/session-001.jsonl", |
medium line 325
Access to hidden dotfiles in home directory
SourceSKILL.md
| 325 | Create YAML files in `~/.cass-memory/starters/`: |
low line 328
Access to hidden dotfiles in home directory
SourceSKILL.md
| 328 | # ~/.cass-memory/starters/django.yaml |
medium line 423
Access to hidden dotfiles in home directory
SourceSKILL.md
| 423 | | **Global** | `~/.cass-memory/traumas.jsonl` | Personal patterns | |
medium line 467
Access to hidden dotfiles in home directory
SourceSKILL.md
| 467 | **Claude Code** (`~/.config/claude/mcp.json`): |
medium line 562
Access to hidden dotfiles in home directory
SourceSKILL.md
| 562 | Config lives at `~/.cass-memory/config.json` (global) and `.cass/config.json` (repo). |
low line 616
Access to hidden dotfiles in home directory
SourceSKILL.md
| 616 | ~/.cass-memory/ # Global (user-level) |
low line 643
Access to hidden dotfiles in home directory
SourceSKILL.md
| 643 | 0 2 * * * /usr/local/bin/cm reflect --days 7 >> ~/.cass-memory/reflect.log 2>&1 |
Scanned on Feb 28, 2026
View Security Dashboard