agentmemory-rest-api

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFEDATA_EXFILTRATIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill instructions direct the agent to access a sensitive credential file located at ~/.agentmemory/secret to obtain an authentication token for API requests.
  • Evidence: REFERENCE.md states the secret is "generated into ~/.agentmemory/secret on first start when it is unset."
  • [COMMAND_EXECUTION]: The skill uses curl commands to interact with a local REST API on localhost:3111. While the target is local, it involves the execution of shell commands to perform memory operations.
  • Evidence: SKILL.md provides multiple curl examples for liveness checks, saving, and searching memories.
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as an interface for a memory system that ingests and recalls content. This creates a surface where malicious instructions could be stored in the memory and later executed by the agent when searching or reflecting on stored context.
  • Ingestion points: Multiple endpoints in REFERENCE.md (e.g., /agentmemory/remember, /agentmemory/observe, /agentmemory/context) accept user-supplied content.
  • Boundary markers: The analyzed files do not specify delimiters or instructions to ignore embedded commands within the memory content.
  • Capability inventory: The agent uses curl to interact with the API surface, which includes operations to update, search, and evolve memories.
  • Sanitization: No sanitization or validation logic for the ingested content is described in the instruction files.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 10:39 AM
Security Audit — agent-trust-hub — agentmemory-rest-api