Back to plugin

Security audit

amem

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent long-term memory plugin that stores and updates agent memories using local Qdrant and a configured LLM endpoint, with the sensitive data flow disclosed.

Install only if you want conversation-derived long-term memory. Use a Qdrant instance and LLM endpoint you trust, set review/cache/data paths deliberately, and enable hooks.allowConversationAccess only when automatic memory write-back is desired.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

Detected: suspicious.env_credential_access

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
dist/index.js:55
Evidence
_dataDir = process.env.AMEM_DATA_DIR || path.join(os.homedir(), ".amem");