supermemory-cli

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill guides the user to install the @supermemory/cli package globally using npm. This is a standard installation procedure for the vendor's official command-line tool.\n- [COMMAND_EXECUTION]: The instructions involve executing numerous CLI commands to interact with the Supermemory API, local file system, and external data connectors.\n- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of data from external sources, which introduces a potential vulnerability to adversarial content.\n
  • Ingestion points: Content is ingested through the add command (supporting files, URLs, and stdin), the remember command, and via automated connectors sync (e.g., Google Drive, Notion) as described in SKILL.md.\n
  • Boundary markers: The instructions do not specify any delimiters or boundary markers to differentiate untrusted external content from system instructions.\n
  • Capability inventory: The tool performs file system reads, network fetches from external URLs, and API communication to store memories and documents.\n
  • Sanitization: There is no mention of sanitization or validation of the ingested data before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 07:21 AM
Security Audit — agent-trust-hub — supermemory-cli