agent-memory-mcp
Fail
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructions direct the user to clone an external repository from
https://github.com/webzler/agentMemory.gitinto the local environment. - [REMOTE_CODE_EXECUTION]: The setup process involves executing
npm installandnpm run compileon the downloaded content, which allows arbitrary scripts defined in the external repository to run during installation and build phases. - [COMMAND_EXECUTION]: The skill requires the execution of multiple shell commands to set up and run an MCP server and a dashboard (
npm run start-server,npm run start-dashboard), which interact with the local filesystem and network. - [PROMPT_INJECTION]: The hybrid memory system creates an attack surface for indirect prompt injection by ingesting and searching untrusted data via
memory_writeandmemory_searchtools without specified boundary markers or sanitization logic. - Ingestion points:
memory_writetool inSKILL.mdcaptures external content into long-term memory. - Boundary markers: Absent; no instructions for delimiters or isolation of memory content are provided.
- Capability inventory: The skill executes shell commands and manages local files via the cloned repository scripts.
- Sanitization: Absent; no mention of filtering or validation for incoming memory content.
Recommendations
- AI detected serious security threats
Audit Metadata