mempalace
Pass
Audited by Gen Agent Trust Hub on May 8, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it is designed to ingest and process untrusted external data.
- Ingestion points: The
mempalace minecommand reads content from local project directories (~/projects/myapp) and chat logs (~/chats/). - Boundary markers: No specific delimiters or instructions to ignore embedded prompts in processed data are documented.
- Capability inventory: The skill provides a suite of 19 tools for reading, writing, and searching the 'memory palace' database, as well as an MCP server for persistent access.
- Sanitization: No evidence of sanitization or filtering of the ingested content is present in the provided scripts.
- [COMMAND_EXECUTION]: The skill utilizes local shell commands for its core operations and automation.
- The documentation instructs users to configure an MCP server using
python3.11 -m mempalace.mcp_server. - The skill implements an automated 'Stop' hook in
settings.jsonthat executeshooks/mempal_save_hook.shupon completion of agent tasks. This script runs a status check and potential context mining via the Python module.
Audit Metadata