Back to skill

Security audit

Install memex — cross-AI memory

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed installer for local AI memory, but it bundles remote code execution, persistent monitoring, and automatic future-context injection in ways users should review carefully.

Install only if you are comfortable with a local memory service that can index sensitive AI and chat history and surface it to future agents. Prefer the manual path over curl-to-bash, inspect any installer first, avoid sudo, decline auto-context unless you want automatic memory injection, and confirm exactly which files, chats, and client configs will be watched or modified.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:84
Finding

Mutable Remote Installer Is Downloaded and Executed Directly

Content
View full analysis
Remediation
View remediation

T06 · System Persistence

Error
Location
SKILL.md:198
Finding

Installation Creates a Persistent Login Daemon With Broad Data Monitoring

Content
View full analysis
Remediation
View remediation

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:204
Finding

Persistent Hooks Automatically Inject Cross-Session Memory Into Future Agent Sessions

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
SKILL.md:109
Finding

Unpinned Global npm Package Installation Creates a Supply-Chain Execution Risk

Content
View full analysis
> ~/.zshrc source ~/.zshrc npm install -g memex-mvp ``` ``` ```markdown If the user **explicitly** picks A (or says "sudo", "fast", "quick"), use sudo: ```sh sudo npm install -g memex-mvp ``` ``` The examples also recommend a mutable latest release: ```sh npm install -g memex-mvp@latest ``` ### Technical Analysis The Skill installs `memex-mvp` globally without pinning a specific audited version or verifying an integrity digest, package signature, or registry provenance. The `@latest` recommendation explicitly resolves mutable registry state at installation time. npm packages may execute lifecycle scripts during installation. A malicious publication, compromised maintainer account, registry compromise, or altered transitive dependency can therefore execute code during installation. The package is then trusted to install persistence, read conversation histories, modify agent configuration, and expose MCP tools. Global installation places package binaries on the user's command path. The documented EACCES workaround also permanently changes the npm global prefix and appends a path entry to `~/.zshrc`, affecting future global npm installations beyond this Skill. The optional `sudo npm install -g memex-mvp` path substantially increases potential impact if the installed package or lifecycle scripts are malicious. The Skill requires explicit confirmation ...[truncated 1482 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (48)

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

The README recommends executing a remotely hosted shell script directly via 'curl ... | bash'. This is dangerous because it grants immediate code execution to whatever content is served at that URL at install time, with no integrity verification, code review step, or version pinning; in this skill context, that risk is amplified because the script also performs daemon setup, config changes, and history backfill.

Content

Scanner excerpt · README.md (reported line 10)May include surrounding context.

md
After you drop the skill into your agent (`~/.claude/skills/` for Claude Code, or your client's equivalent), saying **"install memex"** triggers a guided installation:

1. **Discovery** — read-only checks for which MCP client you're using and what AI data already exists on your machine
2. **Fast path (v1.1+)** — `curl -fsSL https://memex.parallelclaw.ai/install.sh | bash`: one hosted bash script does npm install (with EACCES auto-fix to `~/.npm-global`), daemon setup, v0.8 auto-context hook, history backfill, and `claude mcp add memex` if Claude Code CLI is on PATH. Idempotent.
3. **Fallback: manual five-step** — if curl fails, the user declines, or the agent is inside a GUI client (Cursor/Cline/Continue/Zed) where the MCP config still needs editing: `npm install -g memex-mvp` → MCP config merge → `memex-sync install` → `memex-sync scan`.
4. **MCP config merge** (only needed for GUI clients) — adds a single absolute-path `command` entry into your client's `mcpServers` config. Never overwrites your other servers.
5. **Restart hint + verification commands** — including the v0.7+ CLI fallback (`memex overview`, `memex search "foo"`) so you can verify memex works even if MCP didn't wire up cleanly.

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

Piping curl output directly into bash chains network retrieval to immediate shell execution, removing any inspection boundary. In this skill's context, where the installed software will access local AI histories and modify client configuration, compromise of the remote endpoint or transport assumptions could lead to full user-level code execution and access to sensitive transcripts.

Content

Scanner excerpt · README.md (reported line 63)May include surrounding context.

md
> Best path is the curl one-liner — does npm install (auto-fixes EACCES), daemon, auto-context hook, and history backfill in ~60 seconds. Want me to run:
>
> ```
> curl -fsSL https://memex.parallelclaw.ai/install.sh | bash
> ```
>
> **User:** yes

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill recommends fetching and executing a remote script with curl ... | bash, which bypasses normal verification and executes whatever the server returns at runtime. This is dangerous even when the project is open source, because DNS, hosting, repository state, or transit layers could be compromised and users may not actually inspect the script first.

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

md
| Action | Why | Source-of-truth |
|---|---|---|
| `curl -fsSL https://memex.parallelclaw.ai/install.sh \| bash` | Fast-path installer (the user can `\| less` first to inspect) | [docs/install.sh](https://github.com/parallelclaw/memex-mvp/blob/main/docs/install.sh) — open-source bash, hosted on GitHub Pages |
| `npm install -g memex-mvp` | Manual install (fallback if user declines the curl) | [npmjs.com/package/memex-mvp](https://www.npmjs.com/package/memex-mvp), source: [github.com/parallelclaw/memex-mvp](https://github.com/parallelclaw/memex-mvp) |
| `echo 'export PATH=...' >> ~/.zshrc` | EACCES auto-fix — moves npm prefix to `~/.npm-global` so `npm install -g` works without sudo. **Idempotent** — re-running is safe. | Standard npm prefix workaround [docs.npmjs.com](https://docs.npmjs.com/resolving-eacces-permissions-errors-when-installing-packages-globally) |
| `sudo npm install -g memex-mvp` | Offered as Plan A on EACCES if user explicitly wants quick (not default — skill recommends the no-sudo prefix fix). Skill **never runs sudo without explicit user "yes"**. | — |

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

The skill directs access to agent configuration and settings files such as ~/.claude/settings.json and related client configs. Modifying these files can change agent behavior persistently, enable hooks, and alter what context is exposed in future sessions, so this is a high-sensitivity operation even if intended for setup.

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

md
| `echo 'export PATH=...' >> ~/.zshrc` | EACCES auto-fix — moves npm prefix to `~/.npm-global` so `npm install -g` works without sudo. **Idempotent** — re-running is safe. | Standard npm prefix workaround [docs.npmjs.com](https://docs.npmjs.com/resolving-eacces-permissions-errors-when-installing-packages-globally) |
| `sudo npm install -g memex-mvp` | Offered as Plan A on EACCES if user explicitly wants quick (not default — skill recommends the no-sudo prefix fix). Skill **never runs sudo without explicit user "yes"**. | — |
| `memex-sync install` (LaunchAgent) | Registers a macOS LaunchAgent so memex daemon auto-starts on login. **The daemon itself is local-only**: it watches `~/.claude/projects/`, `~/Downloads/Telegram Desktop/`, etc., and writes to `~/.memex/data/memex.db`. Zero outbound network traffic. | LaunchAgent plist at `~/Library/LaunchAgents/com.parallelclaw.memex.sync.plist` is human-readable |
| Edit `~/.claude/settings.json`, `~/.cursor/mcp.json`, etc. | Adds the MCP-server entry so the user's AI client can call memex tools. Existing entries are preserved (merge, never overwrite). | Each MCP client documents this config format |
| `tell application "Terminal" to do script "claude"` (AppleScript) | Used by the optional clickable notification banner — opens a new Terminal tab + launches `claude` when the user clicks. **Default OFF**. | Requires `brew install terminal-notifier` (optional dep) |
| `brew install terminal-notifier` | Optional dep for clickable banners. Skill mentions it but does NOT install without user OK. | [github.com/julienXX/terminal-notifier](https://github.com/julienXX/terminal-notifier) |

Ssd 3

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill is designed to persist broad cross-application conversation history and later surface it to agents, including importing files from arbitrary disk paths. Even with local-only claims, this materially expands the agent's access to sensitive historical data and increases the blast radius of prompt injection, data over-collection, or later exfiltration by any connected tool.

Content

No source excerpt is available for this finding.

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

The discovery instructions include reading agent-related config paths such as ~/.continue/config.json. While this may be intended for compatibility checks, access to agent configuration is sensitive because it can reveal installed tools, server endpoints, and other local integrations.

Content

Scanner excerpt · SKILL.md (reported line 72)May include surrounding context.

ls -d ~/.claude/projects 2>/dev/null ls -d ~/Library/Application\ Support/Claude/local-agent-mode-sessions 2>/dev/null ls -d ~/Library/Application\ Support/Cursor 2>/dev/null ls ~/.continue/config.json 2>/dev/null ls -d ~/.config/zed 2>/dev/null

text
3. Report to the user in plain language:

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

This line operationalizes the remote-script execution by instructing the agent to show the command, get approval, and then run it. User consent does not remove the core risk: the command executes unpinned remote code whose contents may differ from the referenced source-of-truth or change over time.

Content

Scanner excerpt · SKILL.md (reported line 89)May include surrounding context.

Show this command to the user, explain what it does, get their explicit ok, then run:

sh
curl -fsSL https://memex.parallelclaw.ai/install.sh | bash

What the script does, in order:

Chaining Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

Piping network output directly into bash combines retrieval and execution into a single chain, eliminating an opportunity for verification and making command substitution attacks immediately exploitable. In an agent-execution context this is especially risky because the agent may perform the chain on the user's machine with minimal scrutiny.

Content

Scanner excerpt · SKILL.md (reported line 89)May include surrounding context.

Show this command to the user, explain what it does, get their explicit ok, then run:

sh
curl -fsSL https://memex.parallelclaw.ai/install.sh | bash

What the script does, in order:

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

The hosted installer is documented as adding a hook into ~/.claude/settings.json automatically. This is a persistent behavioral modification to an agent environment performed indirectly through an external script, increasing risk because users may not review the exact changes before execution.

Content

Scanner excerpt · SKILL.md (reported line 95)May include surrounding context.

md
What the script does, in order:
1. Checks Node ≥ 20.
2. `npm install -g memex-mvp` — on EACCES, sets `npm config set prefix ~/.npm-global`, appends PATH to `~/.zshrc`, retries.
3. `memex-sync install` with `--auto-context yes` (Brian Chesky hook into `~/.claude/settings.json` — preserves other hooks).
4. `memex-sync scan` — backfills existing history.
5. `claude mcp add memex --scope user -- memex` if Claude Code CLI is detected.

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

The skill explicitly targets persistent MCP configuration files like ~/.claude/config.json for modification. These files control agent tool connectivity, so incorrect or malicious changes could redirect tool execution, add untrusted servers, or break existing setups.

Content

Scanner excerpt · SKILL.md (reported line 162)May include surrounding context.

md
| Client       | Config file                                         |
|--------------|-----------------------------------------------------|
| Claude Code  | `~/.claude/config.json` (or platform equivalent)    |
| Cursor       | `~/.cursor/mcp.json`                                |
| Cline        | VS Code `settings.json` (`cline.mcpServers`)        |
| Continue     | `~/.continue/config.json`                           |

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

The instructions include modifying ~/.continue/config.json and similar agent config files. Such changes persist across sessions and can alter tool trust boundaries, especially if the added command later has broader access than the user expects.

Content

Scanner excerpt · SKILL.md (reported line 165)May include surrounding context.

md
| Claude Code  | `~/.claude/config.json` (or platform equivalent)    |
| Cursor       | `~/.cursor/mcp.json`                                |
| Cline        | VS Code `settings.json` (`cline.mcpServers`)        |
| Continue     | `~/.continue/config.json`                           |
| Zed          | `~/.config/zed/settings.json` (`context_servers`)   |

Tell the user which one you've inferred and which file you'll edit. If unclear, ask.

Ssd 3

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs the agent to enable live auto-capture, backfill historical conversations, and default to auto-context injection from prior chats. This creates persistent collection and reuse of sensitive data by default, including data the user may not expect to be surfaced automatically in future sessions.

Content

No source excerpt is available for this finding.

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Adding a SessionStart hook to ~/.claude/settings.json gives the installed tool influence over future agent startup behavior and context injection. Hooks are especially sensitive because they run automatically and can affect every subsequent session without fresh review.

Content

Scanner excerpt · SKILL.md (reported line 210)May include surrounding context.

md
Auto-context (Brian Chesky mode):
  When you open Claude Code in a project, memex can inject 500-1500 tokens
  of relevant context so Claude knows what you were doing — without you
  having to ask. Adds a SessionStart hook to ~/.claude/settings.json.
  Other hooks (e.g. gstack) are preserved.

  Enable? [Y/n]

Ssd 4

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The flow intentionally expands from core install into Telegram export capture and then to importing existing chat files, progressively broadening the dataset under management. This upsell pattern is dangerous because it normalizes increasingly invasive collection after trust has already been established, especially for highly sensitive personal conversations.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

The document promotes a remote install script fetched over the network and piped directly into bash as the preferred 'fast-path' installer. This is a classic supply-chain and trust-boundary risk because users execute opaque, mutable remote code without reviewing its contents or verifying integrity.

Content

Scanner excerpt · examples.md (reported line 5)May include surrounding context.

md
Sample interactions when the user invokes this skill. These show typical happy paths and how the skill handles common edge cases.

> **Note (v1.1+):** The skill now leads with the **fast-path one-liner** (`curl -fsSL https://memex.parallelclaw.ai/install.sh | bash`) after Discovery — see Example 0 below. The legacy five-step examples (1–5 below) stay as the fallback when the agent is inside a GUI client (Cursor / Cline / Continue / Zed — still need step 2 manually after the script), the user declines curl, or the script fails.

---

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The fast-path example normalizes executing a remotely hosted script via curl-pipe-to-bash that performs package installation, daemon setup, config edits, history backfill, and MCP wiring. Even with user confirmation, presenting this as the default path without a strong safety warning or inspection step exposes users to supply-chain compromise and opaque system modifications.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

This specific example asks the agent to run a hosted installer script that not only installs software but also configures services, hooks, and data backfill. The combination of remote code execution and broad local side effects makes compromise of the hosting endpoint or script content particularly dangerous.

Content

Scanner excerpt · examples.md (reported line 27)May include surrounding context.

md
> The fast path is a single hosted bash script that does **npm install (with EACCES auto-fix), daemon setup, Brian Chesky auto-context hook, history backfill, and `claude mcp add memex`** all in one go. Idempotent. Want me to run:
>
> ```sh
> curl -fsSL https://memex.parallelclaw.ai/install.sh | bash
> ```
>
> **User:** ok

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

Using '| bash' chains network retrieval directly into command execution, eliminating an opportunity for the user or agent to inspect what will run. In this skill, the chained script is granted authority to alter configs, create background services, and ingest data, so the blast radius of any tampering is substantial.

Content

Scanner excerpt · examples.md (reported line 27)May include surrounding context.

md
> The fast path is a single hosted bash script that does **npm install (with EACCES auto-fix), daemon setup, Brian Chesky auto-context hook, history backfill, and `claude mcp add memex`** all in one go. Idempotent. Want me to run:
>
> ```sh
> curl -fsSL https://memex.parallelclaw.ai/install.sh | bash
> ```
>
> **User:** ok

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
92% confidence
Finding

This example shows automated modification of ~/.claude/settings.json to add an auto-context hook in an agent configuration directory. Writing to agent config is security-sensitive because it can persist behavior changes across sessions, alter trust boundaries, and enable ongoing data capture or tool execution beyond the immediate install flow.

Content

Scanner excerpt · examples.md (reported line 41)May include surrounding context.

md
> ✓ memex 0.9.0 ready at /Users/you/.npm-global/bin/memex
> ▸ Installing memex-sync (LaunchAgent + auto-context hook)...
> ✓ daemon running (PID 41872)
> ✓ Brian Chesky auto-context hook added to ~/.claude/settings.json
> ▸ Backfilling history (memex-sync scan)...
> ✓ 87 conversations indexed
> ▸ Wiring MCP into Claude Code...

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · examples.md (reported line 283)May include surrounding context.

md
>
> Try `memex search "recent topic you discussed"` directly in the terminal — if that returns hits, you've got a fully-working memex; it's just not exposed to your Claude session yet.
>
> Then check your Claude MCP config (`~/.claude/config.json` or equivalent) — the `memex` entry should have an absolute path. Run `which memex` to get it, and verify it's there. If you need to re-do the wiring, ask me again — I'll re-run step 2 of the install.

---

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README promises that 'no data leaves your machine,' but the documented install flow fetches a remote shell script and packages over the network. This is dangerous because users may make trust decisions based on an inaccurate privacy/security claim and execute network-dependent installation steps they would otherwise scrutinize more carefully.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is designed to auto-trigger from broad, natural-language phrases like 'add memory to my AI' or similar variants. In an agent environment, broad trigger matching increases the chance of unintended invocation of an installation workflow that performs discovery, configuration edits, and potentially remote code execution steps.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 81)May include surrounding context.

Install the skill

sh
mkdir -p ~/.claude/skills/install-memex
curl -fsSL https://raw.githubusercontent.com/parallelclaw/memex-mvp/main/skills/install-memex/SKILL.md \
  -o ~/.claude/skills/install-memex/SKILL.md

Session Persistence

Medium
Category
Rogue Agent
Confidence
84% confidence
Finding

The documented install step writes the skill into ~/.claude/skills/install-memex, creating persistent agent behavior across future sessions. Persistence increases risk because a remotely fetched or later-updated skill can continue to influence agent actions long after the initial install, especially given the skill's installation and discovery capabilities.

Content

Scanner excerpt · README.md (reported line 81)May include surrounding context.

Install the skill

sh
mkdir -p ~/.claude/skills/install-memex
curl -fsSL https://raw.githubusercontent.com/parallelclaw/memex-mvp/main/skills/install-memex/SKILL.md \
  -o ~/.claude/skills/install-memex/SKILL.md

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 82)May include surrounding context.

sh
mkdir -p ~/.claude/skills/install-memex
curl -fsSL https://raw.githubusercontent.com/parallelclaw/memex-mvp/main/skills/install-memex/SKILL.md \
  -o ~/.claude/skills/install-memex/SKILL.md

Static analysis

No suspicious patterns detected.