memory-map

Warn

Audited by Gen Agent Trust Hub on Jun 15, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires cloning a repository from an external personal GitHub account (https://github.com/kid-sid/memory_map.git) to acquire the server and lifecycle hook scripts.
  • [COMMAND_EXECUTION]: The installation process instructs the user to modify ~/.claude/settings.json to register lifecycle hooks (UserPromptSubmit, PreCompact, Stop) that automatically execute a local Python script (history_hook.py) whenever a prompt is submitted or the session ends.
  • [DATA_EXFILTRATION]: The skill contains a feature (MCP_HISTORY_EXTERNAL_SUMMARIZE) that, when enabled, sends up to 4,000 characters of recent conversation history—including dialogue, source code, and environment details—to OpenAI's gpt-4o-mini API.
  • [PROMPT_INJECTION]: The skill utilizes an indirect prompt injection surface by ingesting data from .mcp_memory.json and .mcp_history.json at every session start.
  • Ingestion points: Data is loaded from .mcp_memory.json and .mcp_history.json in the project root.
  • Boundary markers: The instructions do not define boundary markers or delimiters to separate historical data from current instructions.
  • Capability inventory: The environment includes local file-write access (save_memory) and the ability to execute code via persistent lifecycle hooks.
  • Sanitization: No sanitization or validation of the stored historical content is performed before it is injected into the agent's context.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 15, 2026, 04:09 PM
Security Audit — agent-trust-hub — memory-map