agent-memory-mcp

Fail

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructions direct the user to clone an external repository from https://github.com/webzler/agentMemory.git into the local environment.
  • [REMOTE_CODE_EXECUTION]: The setup process involves executing npm install and npm run compile on the downloaded content, which allows arbitrary scripts defined in the external repository to run during installation and build phases.
  • [COMMAND_EXECUTION]: The skill requires the execution of multiple shell commands to set up and run an MCP server and a dashboard (npm run start-server, npm run start-dashboard), which interact with the local filesystem and network.
  • [PROMPT_INJECTION]: The hybrid memory system creates an attack surface for indirect prompt injection by ingesting and searching untrusted data via memory_write and memory_search tools without specified boundary markers or sanitization logic.
  • Ingestion points: memory_write tool in SKILL.md captures external content into long-term memory.
  • Boundary markers: Absent; no instructions for delimiters or isolation of memory content are provided.
  • Capability inventory: The skill executes shell commands and manages local files via the cloned repository scripts.
  • Sanitization: Absent; no mention of filtering or validation for incoming memory content.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Apr 11, 2026, 06:18 PM
Security Audit — agent-trust-hub — agent-memory-mcp