Is joelachance/satori safe?
Use with caution. joelachance/satori is not clearly unsafe, but the audit flagged risks to review before you install it. Oathe's behavioral security audit gave the satori skill by joelachance a trust score of 80/100 with 4 findings (2 high).
https://github.com/openclaw/skills/tree/main/skills/joelachance/satori
Is joelachance/satori safe to install?
Satori provides legitimate persistent memory functionality for AI sessions but poses significant privacy and security risks through external data transmission and code execution. The skill sends conversation data to external services and executes downloaded npm packages.
What security issues were found in joelachance/satori?
Category Scores
Findings (4)
HIGH External Data Transmission -30 ▶
The skill explicitly sends conversation data to external services via the Satori CLI, including decisions, preferences, names, deadlines, and strategic information.
HIGH External Code Execution -30 ▶
The skill uses npx to download and execute external npm packages, which represents significant code execution risk.
MEDIUM Silent Behavior Modification -20 ▶
The skill instructs the agent to proactively search and silently incorporate external context without user awareness, modifying normal agent behavior.
MEDIUM Privacy and Transparency Concerns -20 ▶
The skill's silent operation and external data transmission create privacy risks and reduce user awareness of data handling.
Should I install joelachance/satori?
Oathe's verdict for joelachance/satori is CAUTION with a trust score of 80/100. Recommendation: Install with caution.