mempalace

Pass

Audited by Gen Agent Trust Hub on May 8, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it is designed to ingest and process untrusted external data.
  • Ingestion points: The mempalace mine command reads content from local project directories (~/projects/myapp) and chat logs (~/chats/).
  • Boundary markers: No specific delimiters or instructions to ignore embedded prompts in processed data are documented.
  • Capability inventory: The skill provides a suite of 19 tools for reading, writing, and searching the 'memory palace' database, as well as an MCP server for persistent access.
  • Sanitization: No evidence of sanitization or filtering of the ingested content is present in the provided scripts.
  • [COMMAND_EXECUTION]: The skill utilizes local shell commands for its core operations and automation.
  • The documentation instructs users to configure an MCP server using python3.11 -m mempalace.mcp_server.
  • The skill implements an automated 'Stop' hook in settings.json that executes hooks/mempal_save_hook.sh upon completion of agent tasks. This script runs a status check and potential context mining via the Python module.
Audit Metadata
Risk Level
SAFE
Analyzed
May 8, 2026, 03:47 PM
Security Audit — agent-trust-hub — mempalace