Security audit
Engram
Security checks for vulnerabilities and agentic risk
Overview
This skill is a disclosed local memory-system installer, but users should review it carefully because it would modify workspace memory and agent-instruction files and add scheduled local jobs.
Install only if you want a workspace-level memory system that can rewrite MEMORY.md and AGENTS.md and add cron jobs. Because the package here does not include the referenced installer or engine scripts, inspect the actual source code before running any external install command, confirm the dry-run report, and keep the backup manifest so uninstall can restore files.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
