xmemo-vscode — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited xmemo-vscode (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Use this skill when an editor task should use XMemo memory: restore project context, save durable decisions, record working state, or prepare a clean handoff.
Your editor executes development. XMemo lets it remember the project.
XMemo is a user-owned, identity-aware memory layer for multi-agent workflows. It carries useful project context, decisions, preferences, and progress across ChatGPT, Codex, Claude, Cursor, Copilot, Gemini, IDEs, CLIs, and other agents.
Hosted MCP endpoint: https://xmemo.dev/mcp
The extension authenticates with a token stored in the OS keychain (VS Code SecretStorage) and attributes activity with:
X-Memory-OS-Agent-ID: vscodeX-Memory-OS-Agent-Instance-ID: <local-instance-id>OAuth 2.0 (PKCE) in-editor sign-in is the default; token paste is a documented fallback for power users.
At task start: recall focused context for the current repo/subsystem/task; restore a restart snapshot if continuing prior work; fall back to repository evidence if XMemo is unavailable.
During architecture/integration work: capture pending decisions before major tradeoffs; resolve them after implementation or explicit confirmation; save only durable conclusions, not noisy intermediate reasoning.
At handoff: update working state (what changed, what was verified, what remains); create memory TODOs for concrete follow-ups; create a restart snapshot when work is incomplete.
X-Memory-OS-Agent-ID and instance ID as non-secret attribution metadata, not authentication.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.