engram-memory

Warn

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: MEDIUMPROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONPERSISTENCE
Full Analysis
  • [PROMPT_INJECTION]: The skill uses imperative language such as "MANDATORY", "ALWAYS ACTIVE", and "MUST" to force the agent to follow the protocol even without user consent ("do NOT wait for the user to ask", "WITHOUT BEING ASKED").
  • [COMMAND_EXECUTION]: The instructions direct the agent to run engram setup claude-code to repair MCP configuration files and modify permission allowlists, which are sensitive environment-level changes.
  • [DATA_EXFILTRATION]: The protocol requires the agent to proactively record and save session data, including user preferences, technical gotchas, and internal logic decisions, to a persistent store that survives across different projects and sessions.
  • [PERSISTENCE]: The skill explicitly instructs the agent to modify MCP configuration files and handle permission allowlists to ensure the Engram server remains active, and the memory itself is designed to persist user context across session resets.
  • [INDIRECT_PROMPT_INJECTION]:
  • Ingestion points: Data is collected from user input, codebase discoveries, and task completions via the mem_save tool in SKILL.md.
  • Boundary markers: The skill lacks instructions to sanitize or isolate remembered data, instead directing the agent to "search memory PROACTIVELY".
  • Capability inventory: The skill utilizes a broad suite of memory tools (mem_save, mem_search, mem_context) and system-level command execution (engram setup).
  • Sanitization: There is no mention of validation or filtering for data stored in or retrieved from the persistent memory.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 23, 2026, 07:37 PM
Security Audit — agent-trust-hub — engram-memory