memory-map
Warn
Audited by Gen Agent Trust Hub on Jun 15, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires cloning a repository from an external personal GitHub account (
https://github.com/kid-sid/memory_map.git) to acquire the server and lifecycle hook scripts. - [COMMAND_EXECUTION]: The installation process instructs the user to modify
~/.claude/settings.jsonto register lifecycle hooks (UserPromptSubmit,PreCompact,Stop) that automatically execute a local Python script (history_hook.py) whenever a prompt is submitted or the session ends. - [DATA_EXFILTRATION]: The skill contains a feature (
MCP_HISTORY_EXTERNAL_SUMMARIZE) that, when enabled, sends up to 4,000 characters of recent conversation history—including dialogue, source code, and environment details—to OpenAI'sgpt-4o-miniAPI. - [PROMPT_INJECTION]: The skill utilizes an indirect prompt injection surface by ingesting data from
.mcp_memory.jsonand.mcp_history.jsonat every session start. - Ingestion points: Data is loaded from
.mcp_memory.jsonand.mcp_history.jsonin the project root. - Boundary markers: The instructions do not define boundary markers or delimiters to separate historical data from current instructions.
- Capability inventory: The environment includes local file-write access (
save_memory) and the ability to execute code via persistent lifecycle hooks. - Sanitization: No sanitization or validation of the stored historical content is performed before it is injected into the agent's context.
Audit Metadata