
Product
PHP and Composer Support Is Now in Beta
Socket’s PHP and Composer support is now in Beta for all customers, with PHP reachability analysis generally available.
memtrust-cli
Advanced tools
npx-runnable wrapper for the memtrust agent-memory benchmark harness. Bootstraps a verified copy of Astral's uv to fetch and run memtrust-cli from PyPI -- no Python toolchain to provision by hand.
npx-runnable wrapper for memtrust, an open agent-memory eval harness that benchmarks memory backends (MemPalace, Mem0, Zep/Graphiti, OpenViking) against real failure modes — silent write loss, contradiction handling, ranking degradation, and more.
This package does not implement memtrust itself. It bootstraps a genuine, SHA-256-verified copy of
Astral's uv for your platform, then uses it to fetch and run
the real memtrust-cli package from PyPI — no separate Python toolchain to install by hand.
npx memtrust-cli --help
or, if installed globally:
npm install -g memtrust-cli
memtrust --help
The first run downloads memtrust-cli from PyPI via uv tool run --from memtrust-cli memtrust and
caches it; subsequent runs reuse the cache.
macOS (arm64/x64), Linux (arm64/x64), Windows (arm64/x64) — the matching platform binary is pulled
in automatically via optionalDependencies.
Apache-2.0
FAQs
npx-runnable wrapper for the memtrust agent-memory benchmark harness. Bootstraps a verified copy of Astral's uv to fetch and run memtrust-cli from PyPI -- no Python toolchain to provision by hand.
The npm package memtrust-cli receives a total of 22 weekly downloads. As such, memtrust-cli popularity was classified as not popular.
We found that memtrust-cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.

Product
Socket’s PHP and Composer support is now in Beta for all customers, with PHP reachability analysis generally available.

Product
Socket is bringing experimental protection to Firefox, scanning 97,000+ extensions in Mozilla's official directory for malware and risky updates.

Research
/Security News
Three compromised Rust crates pulled in a malicious dependency that downloaded and executed cross-platform malware during Cargo builds.