agent-memory-mcp

Warn

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires cloning a repository from an unverified source at 'https://github.com/webzler/agentMemory.git'.
  • [COMMAND_EXECUTION]: The installation and setup flow involves executing shell commands ('npm install' and 'npm run compile') that run arbitrary code from the downloaded third-party repository.
  • [PROMPT_INJECTION]: The skill provides tools ('memory_write', 'memory_search') that create an indirect prompt injection surface:
  • Ingestion points: Untrusted data enters the agent context through the tools defined in 'SKILL.md' that write to the local memory bank.
  • Boundary markers: The instructions lack delimiters or 'ignore embedded instructions' warnings for the agent when processing retrieved memories.
  • Capability inventory: The skill can read/write to the filesystem and run a local MCP server.
  • Sanitization: There is no mention of data validation or content filtering for the stored knowledge.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 28, 2026, 05:45 AM
Security Audit — agent-trust-hub — agent-memory-mcp