agent-memory-mcp

Warn

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires cloning a repository from https://github.com/webzler/agentMemory.git which is not associated with a trusted organization or well-known service.
  • [REMOTE_CODE_EXECUTION]: The installation and execution steps involve running npm install and npm run start-server on the code downloaded from the untrusted repository.
  • [INDIRECT_PROMPT_INJECTION]: The skill implements a persistent memory system that provides an attack surface for indirect prompt injection. 1. Ingestion points: The memory_write tool accepts content in SKILL.md. 2. Boundary markers: The documentation does not specify the use of delimiters or boundary markers to isolate instructions from data. 3. Capability inventory: The skill provides long-term persistent storage and retrieval tools including memory_read and memory_search. 4. Sanitization: No sanitization or escaping of stored content is described, allowing potentially malicious instructions to be retrieved into the agent context.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 14, 2026, 02:31 PM
Security Audit — agent-trust-hub — agent-memory-mcp