agentmemory-rest-api
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEDATA_EXFILTRATIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill instructions direct the agent to access a sensitive credential file located at
~/.agentmemory/secretto obtain an authentication token for API requests. - Evidence:
REFERENCE.mdstates the secret is "generated into ~/.agentmemory/secret on first start when it is unset." - [COMMAND_EXECUTION]: The skill uses
curlcommands to interact with a local REST API onlocalhost:3111. While the target is local, it involves the execution of shell commands to perform memory operations. - Evidence:
SKILL.mdprovides multiplecurlexamples for liveness checks, saving, and searching memories. - [INDIRECT_PROMPT_INJECTION]: The skill acts as an interface for a memory system that ingests and recalls content. This creates a surface where malicious instructions could be stored in the memory and later executed by the agent when searching or reflecting on stored context.
- Ingestion points: Multiple endpoints in
REFERENCE.md(e.g.,/agentmemory/remember,/agentmemory/observe,/agentmemory/context) accept user-supplied content. - Boundary markers: The analyzed files do not specify delimiters or instructions to ignore embedded commands within the memory content.
- Capability inventory: The agent uses
curlto interact with the API surface, which includes operations to update, search, and evolve memories. - Sanitization: No sanitization or validation logic for the ingested content is described in the instruction files.
Audit Metadata