agent-memory-mcp
Warn
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires cloning a repository from an unverified source at 'https://github.com/webzler/agentMemory.git'.
- [COMMAND_EXECUTION]: The installation and setup flow involves executing shell commands ('npm install' and 'npm run compile') that run arbitrary code from the downloaded third-party repository.
- [PROMPT_INJECTION]: The skill provides tools ('memory_write', 'memory_search') that create an indirect prompt injection surface:
- Ingestion points: Untrusted data enters the agent context through the tools defined in 'SKILL.md' that write to the local memory bank.
- Boundary markers: The instructions lack delimiters or 'ignore embedded instructions' warnings for the agent when processing retrieved memories.
- Capability inventory: The skill can read/write to the filesystem and run a local MCP server.
- Sanitization: There is no mention of data validation or content filtering for the stored knowledge.
Audit Metadata