supermemory-cli
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill guides the user to install the
@supermemory/clipackage globally using npm. This is a standard installation procedure for the vendor's official command-line tool.\n- [COMMAND_EXECUTION]: The instructions involve executing numerous CLI commands to interact with the Supermemory API, local file system, and external data connectors.\n- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of data from external sources, which introduces a potential vulnerability to adversarial content.\n - Ingestion points: Content is ingested through the
addcommand (supporting files, URLs, and stdin), theremembercommand, and via automatedconnectorssync (e.g., Google Drive, Notion) as described inSKILL.md.\n - Boundary markers: The instructions do not specify any delimiters or boundary markers to differentiate untrusted external content from system instructions.\n
- Capability inventory: The tool performs file system reads, network fetches from external URLs, and API communication to store memories and documents.\n
- Sanitization: There is no mention of sanitization or validation of the ingested data before it is processed by the agent.
Audit Metadata