T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:84- Finding
Mutable Remote Installer Is Downloaded and Executed Directly
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed installer for local AI memory, but it bundles remote code execution, persistent monitoring, and automatic future-context injection in ways users should review carefully.
Install only if you are comfortable with a local memory service that can index sensitive AI and chat history and surface it to future agents. Prefer the manual path over curl-to-bash, inspect any installer first, avoid sudo, decline auto-context unless you want automatic memory injection, and confirm exactly which files, chats, and client configs will be watched or modified.
SKILL.md:84Mutable Remote Installer Is Downloaded and Executed Directly
SKILL.md:198Installation Creates a Persistent Login Daemon With Broad Data Monitoring
SKILL.md:204Persistent Hooks Automatically Inject Cross-Session Memory Into Future Agent Sessions
SKILL.md:109Unpinned Global npm Package Installation Creates a Supply-Chain Execution Risk
The README recommends executing a remotely hosted shell script directly via 'curl ... | bash'. This is dangerous because it grants immediate code execution to whatever content is served at that URL at install time, with no integrity verification, code review step, or version pinning; in this skill context, that risk is amplified because the script also performs daemon setup, config changes, and history backfill.
After you drop the skill into your agent (`~/.claude/skills/` for Claude Code, or your client's equivalent), saying **"install memex"** triggers a guided installation:
1. **Discovery** — read-only checks for which MCP client you're using and what AI data already exists on your machine
2. **Fast path (v1.1+)** — `curl -fsSL https://memex.parallelclaw.ai/install.sh | bash`: one hosted bash script does npm install (with EACCES auto-fix to `~/.npm-global`), daemon setup, v0.8 auto-context hook, history backfill, and `claude mcp add memex` if Claude Code CLI is on PATH. Idempotent.
3. **Fallback: manual five-step** — if curl fails, the user declines, or the agent is inside a GUI client (Cursor/Cline/Continue/Zed) where the MCP config still needs editing: `npm install -g memex-mvp` → MCP config merge → `memex-sync install` → `memex-sync scan`.
4. **MCP config merge** (only needed for GUI clients) — adds a single absolute-path `command` entry into your client's `mcpServers` config. Never overwrites your other servers.
5. **Restart hint + verification commands** — including the v0.7+ CLI fallback (`memex overview`, `memex search "foo"`) so you can verify memex works even if MCP didn't wire up cleanly.
Piping curl output directly into bash chains network retrieval to immediate shell execution, removing any inspection boundary. In this skill's context, where the installed software will access local AI histories and modify client configuration, compromise of the remote endpoint or transport assumptions could lead to full user-level code execution and access to sensitive transcripts.
> Best path is the curl one-liner — does npm install (auto-fixes EACCES), daemon, auto-context hook, and history backfill in ~60 seconds. Want me to run:
>
> ```
> curl -fsSL https://memex.parallelclaw.ai/install.sh | bash
> ```
>
> **User:** yes
The skill recommends fetching and executing a remote script with curl ... | bash, which bypasses normal verification and executes whatever the server returns at runtime. This is dangerous even when the project is open source, because DNS, hosting, repository state, or transit layers could be compromised and users may not actually inspect the script first.
| Action | Why | Source-of-truth |
|---|---|---|
| `curl -fsSL https://memex.parallelclaw.ai/install.sh \| bash` | Fast-path installer (the user can `\| less` first to inspect) | [docs/install.sh](https://github.com/parallelclaw/memex-mvp/blob/main/docs/install.sh) — open-source bash, hosted on GitHub Pages |
| `npm install -g memex-mvp` | Manual install (fallback if user declines the curl) | [npmjs.com/package/memex-mvp](https://www.npmjs.com/package/memex-mvp), source: [github.com/parallelclaw/memex-mvp](https://github.com/parallelclaw/memex-mvp) |
| `echo 'export PATH=...' >> ~/.zshrc` | EACCES auto-fix — moves npm prefix to `~/.npm-global` so `npm install -g` works without sudo. **Idempotent** — re-running is safe. | Standard npm prefix workaround [docs.npmjs.com](https://docs.npmjs.com/resolving-eacces-permissions-errors-when-installing-packages-globally) |
| `sudo npm install -g memex-mvp` | Offered as Plan A on EACCES if user explicitly wants quick (not default — skill recommends the no-sudo prefix fix). Skill **never runs sudo without explicit user "yes"**. | — |
The skill directs access to agent configuration and settings files such as ~/.claude/settings.json and related client configs. Modifying these files can change agent behavior persistently, enable hooks, and alter what context is exposed in future sessions, so this is a high-sensitivity operation even if intended for setup.
| `echo 'export PATH=...' >> ~/.zshrc` | EACCES auto-fix — moves npm prefix to `~/.npm-global` so `npm install -g` works without sudo. **Idempotent** — re-running is safe. | Standard npm prefix workaround [docs.npmjs.com](https://docs.npmjs.com/resolving-eacces-permissions-errors-when-installing-packages-globally) |
| `sudo npm install -g memex-mvp` | Offered as Plan A on EACCES if user explicitly wants quick (not default — skill recommends the no-sudo prefix fix). Skill **never runs sudo without explicit user "yes"**. | — |
| `memex-sync install` (LaunchAgent) | Registers a macOS LaunchAgent so memex daemon auto-starts on login. **The daemon itself is local-only**: it watches `~/.claude/projects/`, `~/Downloads/Telegram Desktop/`, etc., and writes to `~/.memex/data/memex.db`. Zero outbound network traffic. | LaunchAgent plist at `~/Library/LaunchAgents/com.parallelclaw.memex.sync.plist` is human-readable |
| Edit `~/.claude/settings.json`, `~/.cursor/mcp.json`, etc. | Adds the MCP-server entry so the user's AI client can call memex tools. Existing entries are preserved (merge, never overwrite). | Each MCP client documents this config format |
| `tell application "Terminal" to do script "claude"` (AppleScript) | Used by the optional clickable notification banner — opens a new Terminal tab + launches `claude` when the user clicks. **Default OFF**. | Requires `brew install terminal-notifier` (optional dep) |
| `brew install terminal-notifier` | Optional dep for clickable banners. Skill mentions it but does NOT install without user OK. | [github.com/julienXX/terminal-notifier](https://github.com/julienXX/terminal-notifier) |
The skill is designed to persist broad cross-application conversation history and later surface it to agents, including importing files from arbitrary disk paths. Even with local-only claims, this materially expands the agent's access to sensitive historical data and increases the blast radius of prompt injection, data over-collection, or later exfiltration by any connected tool.
The discovery instructions include reading agent-related config paths such as ~/.continue/config.json. While this may be intended for compatibility checks, access to agent configuration is sensitive because it can reveal installed tools, server endpoints, and other local integrations.
ls -d ~/.claude/projects 2>/dev/null ls -d ~/Library/Application\ Support/Claude/local-agent-mode-sessions 2>/dev/null ls -d ~/Library/Application\ Support/Cursor 2>/dev/null ls ~/.continue/config.json 2>/dev/null ls -d ~/.config/zed 2>/dev/null
3. Report to the user in plain language:
This line operationalizes the remote-script execution by instructing the agent to show the command, get approval, and then run it. User consent does not remove the core risk: the command executes unpinned remote code whose contents may differ from the referenced source-of-truth or change over time.
Show this command to the user, explain what it does, get their explicit ok, then run:
curl -fsSL https://memex.parallelclaw.ai/install.sh | bash
What the script does, in order:
Piping network output directly into bash combines retrieval and execution into a single chain, eliminating an opportunity for verification and making command substitution attacks immediately exploitable. In an agent-execution context this is especially risky because the agent may perform the chain on the user's machine with minimal scrutiny.
Show this command to the user, explain what it does, get their explicit ok, then run:
curl -fsSL https://memex.parallelclaw.ai/install.sh | bash
What the script does, in order:
The hosted installer is documented as adding a hook into ~/.claude/settings.json automatically. This is a persistent behavioral modification to an agent environment performed indirectly through an external script, increasing risk because users may not review the exact changes before execution.
What the script does, in order:
1. Checks Node ≥ 20.
2. `npm install -g memex-mvp` — on EACCES, sets `npm config set prefix ~/.npm-global`, appends PATH to `~/.zshrc`, retries.
3. `memex-sync install` with `--auto-context yes` (Brian Chesky hook into `~/.claude/settings.json` — preserves other hooks).
4. `memex-sync scan` — backfills existing history.
5. `claude mcp add memex --scope user -- memex` if Claude Code CLI is detected.
The skill explicitly targets persistent MCP configuration files like ~/.claude/config.json for modification. These files control agent tool connectivity, so incorrect or malicious changes could redirect tool execution, add untrusted servers, or break existing setups.
| Client | Config file |
|--------------|-----------------------------------------------------|
| Claude Code | `~/.claude/config.json` (or platform equivalent) |
| Cursor | `~/.cursor/mcp.json` |
| Cline | VS Code `settings.json` (`cline.mcpServers`) |
| Continue | `~/.continue/config.json` |
The instructions include modifying ~/.continue/config.json and similar agent config files. Such changes persist across sessions and can alter tool trust boundaries, especially if the added command later has broader access than the user expects.
| Claude Code | `~/.claude/config.json` (or platform equivalent) |
| Cursor | `~/.cursor/mcp.json` |
| Cline | VS Code `settings.json` (`cline.mcpServers`) |
| Continue | `~/.continue/config.json` |
| Zed | `~/.config/zed/settings.json` (`context_servers`) |
Tell the user which one you've inferred and which file you'll edit. If unclear, ask.
The skill instructs the agent to enable live auto-capture, backfill historical conversations, and default to auto-context injection from prior chats. This creates persistent collection and reuse of sensitive data by default, including data the user may not expect to be surfaced automatically in future sessions.
Adding a SessionStart hook to ~/.claude/settings.json gives the installed tool influence over future agent startup behavior and context injection. Hooks are especially sensitive because they run automatically and can affect every subsequent session without fresh review.
Auto-context (Brian Chesky mode):
When you open Claude Code in a project, memex can inject 500-1500 tokens
of relevant context so Claude knows what you were doing — without you
having to ask. Adds a SessionStart hook to ~/.claude/settings.json.
Other hooks (e.g. gstack) are preserved.
Enable? [Y/n]
The flow intentionally expands from core install into Telegram export capture and then to importing existing chat files, progressively broadening the dataset under management. This upsell pattern is dangerous because it normalizes increasingly invasive collection after trust has already been established, especially for highly sensitive personal conversations.
The document promotes a remote install script fetched over the network and piped directly into bash as the preferred 'fast-path' installer. This is a classic supply-chain and trust-boundary risk because users execute opaque, mutable remote code without reviewing its contents or verifying integrity.
Sample interactions when the user invokes this skill. These show typical happy paths and how the skill handles common edge cases.
> **Note (v1.1+):** The skill now leads with the **fast-path one-liner** (`curl -fsSL https://memex.parallelclaw.ai/install.sh | bash`) after Discovery — see Example 0 below. The legacy five-step examples (1–5 below) stay as the fallback when the agent is inside a GUI client (Cursor / Cline / Continue / Zed — still need step 2 manually after the script), the user declines curl, or the script fails.
---
The fast-path example normalizes executing a remotely hosted script via curl-pipe-to-bash that performs package installation, daemon setup, config edits, history backfill, and MCP wiring. Even with user confirmation, presenting this as the default path without a strong safety warning or inspection step exposes users to supply-chain compromise and opaque system modifications.
This specific example asks the agent to run a hosted installer script that not only installs software but also configures services, hooks, and data backfill. The combination of remote code execution and broad local side effects makes compromise of the hosting endpoint or script content particularly dangerous.
> The fast path is a single hosted bash script that does **npm install (with EACCES auto-fix), daemon setup, Brian Chesky auto-context hook, history backfill, and `claude mcp add memex`** all in one go. Idempotent. Want me to run:
>
> ```sh
> curl -fsSL https://memex.parallelclaw.ai/install.sh | bash
> ```
>
> **User:** ok
Using '| bash' chains network retrieval directly into command execution, eliminating an opportunity for the user or agent to inspect what will run. In this skill, the chained script is granted authority to alter configs, create background services, and ingest data, so the blast radius of any tampering is substantial.
> The fast path is a single hosted bash script that does **npm install (with EACCES auto-fix), daemon setup, Brian Chesky auto-context hook, history backfill, and `claude mcp add memex`** all in one go. Idempotent. Want me to run:
>
> ```sh
> curl -fsSL https://memex.parallelclaw.ai/install.sh | bash
> ```
>
> **User:** ok
This example shows automated modification of ~/.claude/settings.json to add an auto-context hook in an agent configuration directory. Writing to agent config is security-sensitive because it can persist behavior changes across sessions, alter trust boundaries, and enable ongoing data capture or tool execution beyond the immediate install flow.
> ✓ memex 0.9.0 ready at /Users/you/.npm-global/bin/memex
> ▸ Installing memex-sync (LaunchAgent + auto-context hook)...
> ✓ daemon running (PID 41872)
> ✓ Brian Chesky auto-context hook added to ~/.claude/settings.json
> ▸ Backfilling history (memex-sync scan)...
> ✓ 87 conversations indexed
> ▸ Wiring MCP into Claude Code...
Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.
>
> Try `memex search "recent topic you discussed"` directly in the terminal — if that returns hits, you've got a fully-working memex; it's just not exposed to your Claude session yet.
>
> Then check your Claude MCP config (`~/.claude/config.json` or equivalent) — the `memex` entry should have an absolute path. Run `which memex` to get it, and verify it's there. If you need to re-do the wiring, ask me again — I'll re-run step 2 of the install.
---
The README promises that 'no data leaves your machine,' but the documented install flow fetches a remote shell script and packages over the network. This is dangerous because users may make trust decisions based on an inaccurate privacy/security claim and execute network-dependent installation steps they would otherwise scrutinize more carefully.
The skill is designed to auto-trigger from broad, natural-language phrases like 'add memory to my AI' or similar variants. In an agent environment, broad trigger matching increases the chance of unintended invocation of an installation workflow that performs discovery, configuration edits, and potentially remote code execution steps.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
mkdir -p ~/.claude/skills/install-memex
curl -fsSL https://raw.githubusercontent.com/parallelclaw/memex-mvp/main/skills/install-memex/SKILL.md \
-o ~/.claude/skills/install-memex/SKILL.md
The documented install step writes the skill into ~/.claude/skills/install-memex, creating persistent agent behavior across future sessions. Persistence increases risk because a remotely fetched or later-updated skill can continue to influence agent actions long after the initial install, especially given the skill's installation and discovery capabilities.
mkdir -p ~/.claude/skills/install-memex
curl -fsSL https://raw.githubusercontent.com/parallelclaw/memex-mvp/main/skills/install-memex/SKILL.md \
-o ~/.claude/skills/install-memex/SKILL.md
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
mkdir -p ~/.claude/skills/install-memex
curl -fsSL https://raw.githubusercontent.com/parallelclaw/memex-mvp/main/skills/install-memex/SKILL.md \
-o ~/.claude/skills/install-memex/SKILL.md
No suspicious patterns detected.