mempalace
Fail
Audited by Snyk on Jul 30, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 0.80). Personal/unknown GitHub repository is listed as the source for code the skill instructs you to run locally — downloading and executing code from an unvetted personal repo can deliver malware.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). The MemPalace runtime workflow ingests only outsider-supplied text passed as explicit tool arguments (e.g.,
mempalace_search.queryormempalace_add_drawer.content), rather than reading from any external outsider-authored feed/queue by itself.
Issues (2)
E005
CRITICALSuspicious download URL detected in skill instructions.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata