agent-memory-mcp

Warn

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The setup instructions direct the agent to clone a repository from https://github.com/webzler/agentMemory.git. This involves fetching external code from a source that is not verified or part of a trusted organization.- [COMMAND_EXECUTION]: The skill requires executing shell commands (npm install, npm run compile, npm run start-server) to build and run the downloaded code. This creates a risk if the downloaded code contains malicious logic.- [INDIRECT_PROMPT_INJECTION]: The skill manages agent memory by reading and writing knowledge from project workspaces.
  • Ingestion points: Data enters the system via project documentation and workspace content analyzed for memories.
  • Boundary markers: The instructions do not specify any delimiters or safety markers to prevent the agent from obeying instructions embedded in stored memories.
  • Capability inventory: The skill uses tools (memory_read, memory_write, memory_search) to manage persistent data.
  • Sanitization: No explicit sanitization of memory content is mentioned.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 14, 2026, 07:19 AM
Security Audit — agent-trust-hub — agent-memory-mcp