Caveat verdict
engram
engramclaw
Local memory persistence skill for AI agents using named binaries from brew/npm; agent decides when to save memories and all described operations are local with no external data exfiltration.
β Flagged for review β coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis β not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Permission integrity
credential_access
package_install
agent_memory
Findings (2)
References sudo β requests elevated privileges
SKILL.md Β· prose Β· downgraded Β· sudo
References agent memory files
SKILL.md Β· code Β· MEMORY.md
Permissions & capabilities
Requires 2 system binaries.
package_installagent_memorycredential_access Is this flag fair?
Thanks β recorded.