Is MemPalace/mempalace safe?
Use with caution. MemPalace/mempalace is not clearly unsafe, but the audit flagged risks to review before you install it. Oathe's behavioral security audit gave the mempalace skill by MemPalace a trust score of 73/100 with 13 findings, none critical or high.
https://github.com/MemPalace/mempalace
Is MemPalace/mempalace safe to install?
MemPalace is a legitimate, technically sophisticated local AI memory system with no evidence of malicious intent, canary exfiltration, or unexpected network activity during installation. However, it presents meaningful concerns warranting caution: shell hooks automatically mine and index all agent conversations without per-session approval, the skill enforces mandatory behavior modification and persona injection across every session, and the shared-brain multi-agent mode creates cross-user trust boundaries where a compromised agent could access all stored memories. The optional LLM refinement feature can transmit conversation content to external APIs, and the broad mempalace_mine capability has no documented path restrictions.
What security issues were found in MemPalace/mempalace?
Category Scores
Findings (13)
MEDIUM Mandatory Session Protocol Override -15 ▶
Multiple skill variants use 'FOLLOW THIS EVERY SESSION', 'ON WAKE-UP: Call mempalace_status', and 'BEFORE RESPONDING about any person, project, or past event: call mempalace_search or mempalace_kg_query FIRST' language. This enforces mandatory MCP tool invocations on every agent session start and every relevant user query, fundamentally altering baseline agent behavior without the user needing to request it each time.
MEDIUM Persona and Identity Injection -10 ▶
The mempalace-recall skill contains an explicit Identity section instructing the agent to adopt a specific expert persona. This overrides the agent's default self-representation and could affect how the agent reasons about its own capabilities and authority when memory-related queries arise.
LOW Non-Standard External Documentation URL -5 ▶
The antigravity-plugin variant of the mempalace-recall skill lists 'https://antigravity.google/docs' as official Antigravity documentation. This URL format is atypical for Google-hosted documentation (which normally uses docs.google.com or similar). If an agent attempts to fetch or validate this URL, behavior could be unexpected.
MEDIUM Automatic Shell Hook Execution on Agent Lifecycle Events -25 ▶
The .claude-plugin/hooks/ directory contains three shell scripts that Claude Code automatically executes on agent lifecycle events: mempal-stop-hook.sh (PostToolUse stop), mempal-session-end-hook.sh (session end), and mempal-precompact-hook.sh (pre-compaction). According to test_save_hook_mines.py and the skill documentation, these hooks call 'mempalace mine --mode convos' on conversation transcripts using TRANSCRIPT_PATH, mining and indexing all conversations into the palace without requiring explicit user approval on each session.
LOW Rust Native Extension Included -8 ▶
The repository includes crates/mempalace-py/, a Rust PyO3 binding compiled to a native shared library (.so/.pyd) loaded directly into Python. Native extensions execute machine code directly, bypass Python's sandboxing mechanisms, and have unrestricted system call access. While the visible source code does not show malicious intent, native binaries warrant elevated scrutiny.
LOW Conversation Content Transmission to External LLM APIs -12 ▶
The optional LLM-based closet regeneration feature (closet_llm.py) transmits conversation content to external LLM API endpoints. The endpoint, API key, and model are configured via LLM_ENDPOINT, LLM_KEY, and LLM_MODEL environment variables, meaning content could be sent to any third-party LLM provider the operator configures. While opt-in, this is an outbound data flow containing indexed conversation material.
LOW Silent Background Conversation Auto-Save Mode -12 ▶
The skill supports a silent_save mode via mempalace_hook_settings where conversation indexing occurs without any MCP-level visibility to the user. The dedicated mempalace_memories_filed_away tool exists specifically to 'acknowledge the latest silent auto-save checkpoint' and returns 'how many messages were tucked into drawers since the last ack', confirming a persistent background process is silently collecting and storing conversation content between explicit user interactions.
LOW Unrestricted Directory Mining Capability -8 ▶
The mempalace_mine MCP tool accepts any filesystem path as the source parameter with no documented access controls or path restrictions. The SKILL.md instructs agents to call this tool 'when the user asks to import files' but provides no guardrails against mining sensitive directories (e.g., ~/.ssh/, ~/.aws/, project secret stores). All files in the mined directory would be indexed and stored verbatim in the palace.
LOW Outbound Network Connection Required for Installation -8 ▶
Installation requires an outbound HTTPS connection to GitHub (140.82.121.4:443) to clone the repository. While this is entirely expected for a GitHub-hosted skill, it represents a network dependency and supply chain trust point. No unexpected third-party connections were observed, no new persistent network listeners were established, and the connection diff shows no changes after installation.
INFO Canary Files Accessed During Audit Window — Attributed to Monitoring Setup -5 ▶
Honeypot files (.env, .ssh/id_rsa, .aws/credentials, .npmrc, .docker/config.json, .config/gcloud/application_default_credentials.json) were opened at timestamp 1789096617.331 (03:16:57). The git clone began at timestamp 1789096622.849 (03:17:02) — approximately 5 seconds later. Process execution records show sudo-level system setup activity at this timestamp, consistent with OATHE monitoring baseline initialization rather than the cloned repository. All canary files remain intact with no content modification or external exfiltration detected.
MEDIUM Shared-Brain Multi-Agent Trust Model Creates Cross-User Exposure -20 ▶
The shared-brain hub mode allows multiple agents on different machines to read from and write to the same memory palace using bearer tokens. A compromised agent, a rogue team member's agent, or an attacker who obtains a valid hub token could read all stored memories from all users who have ever stored data in that palace. The logstream coordination system creates persistent inter-agent communication channels (mempalace_event_wait, mempalace_event_list) that survive individual session boundaries, enabling reconnaissance across agent sessions.
LOW Immutable Logstream Enables Persistent Task Injection -8 ▶
The skill explicitly states 'logstream events are immutable' — once an event (including task.request events) is written to the shared logstream, it cannot be revoked or modified. An attacker with logstream write access could inject persistent task directives that any monitoring agent would receive and potentially act upon, even after the attacker loses access.
LOW Duplicated Skill Content Multiplies Injection Surface -5 ▶
The repository contains three substantially identical copies of each skill (mempalace setup, mempalace-recall, mempalace-task) targeting different platforms: Claude Code (.claude-plugin/), Cursor/Antigravity (.cursor-plugin/, .antigravity-plugin/), and Codex (.codex-plugin/), plus additional copies in skills/ and integrations/openclaw/. Minor platform-specific variations exist between copies. This redundancy multiplies the prompt injection surface and makes full auditing more difficult, as each variant must be individually reviewed.
Should I install MemPalace/mempalace?
Oathe's verdict for MemPalace/mempalace is CAUTION with a trust score of 73/100. Recommendation: Install with caution.