arise-mempalace
Fail
Audited by Snyk on Jul 17, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 0.70). Moderately suspicious: the package installs a native MCP binary and the docs live on an unverified personal domain (mempalaceofficial.com), and distributing executables from a small/unverified GitHub repo or personal site increases the risk of malware.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). SKILL.md describes Claude Code auto-save hooks that “mine the JSONL transcript directly (raw, lossless)” and “prompt the AI to save key context,” meaning the agent ingests free-form conversation/tool-output text authored by other participants in the Claude Code transcript (outsider messages) into the LLM context.
Issues (2)
E005
CRITICALSuspicious download URL detected in skill instructions.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata