Local-first Memory Framework for AI Agents · 99.2% LongMemEval-S retrieval @ k=10 · Supports Claude · Antigravity · LangChain · Hermes · Gemini · OpenCode · OpenClaw · MCP-native and plugins · Hybrid search (FTS5 + vector + MMR) · GDPR · FIPS 140-3 ready · 100% local (fully offline) or cloud capable
- capability exposure inferred + 35
- recent drift inferred + 20
- tool safety inferred + 19
- trust mitigators mixed − 17
inferred mixed
The A–E grade is our heuristic synthesis — a "review this" prompt, not a verdict. Each factor is tagged by what backs it: attested (a verifiable record), reported (a third party's claim), or inferred (our own heuristic, e.g. permissions). See methodology.
graded 5m ago · see ecosystem CVEs →
- C · 58 → C · 57
- D · 66 → C · 58
- D · 64 → D · 66
- C · 56 → D · 64
- A · 0 → C · 56
No known CVEs for this server.
- high dangerous code
committed secret: Anthropic key · dynamic exec: eval()/exec(), __import__(), __import__ sink
- medium dangerous code
env-secret-flows-to-network-py: An environment value (often a secret/token) flows into a network call — possible credential exfiltration. (skynetcmd-m3-memory-a9d2161/bin/news_fetc
- medium dangerous code
env-secret-flows-to-network-py: An environment value (often a secret/token) flows into a network call — possible credential exfiltration. (skynetcmd-m3-memory-a9d2161/bin/test_unif
- medium toxic flow (lethal trifecta)
lethal trifecta reachable across connected servers: this server can exfiltrate (network) while a connected dependency supplies private-data access / untrusted-content ingestion
- low exfiltration combo
sensitive read and network capabilities split across this server's tools
analyzed commit a9d2161 · analyzer v31 · 2d ago
skills & prompt files 22
- skill skynetcmd-m3-memory-a9d2161/.antigravity-plugin/skills/m3-agents/SKILL.md
- skill skynetcmd-m3-memory-a9d2161/.antigravity-plugin/skills/m3-export/SKILL.md
- skill skynetcmd-m3-memory-a9d2161/.antigravity-plugin/skills/m3-find-in-chat/SKILL.md
- skill skynetcmd-m3-memory-a9d2161/.antigravity-plugin/skills/m3-forget/SKILL.md
- skill skynetcmd-m3-memory-a9d2161/.antigravity-plugin/skills/m3-get/SKILL.md
- skill skynetcmd-m3-memory-a9d2161/.antigravity-plugin/skills/m3-graph/SKILL.md
- skill skynetcmd-m3-memory-a9d2161/.antigravity-plugin/skills/m3-guide/SKILL.md
- skill skynetcmd-m3-memory-a9d2161/.antigravity-plugin/skills/m3-health/SKILL.md
- skill skynetcmd-m3-memory-a9d2161/.antigravity-plugin/skills/m3-help/SKILL.md
- skill skynetcmd-m3-memory-a9d2161/.antigravity-plugin/skills/m3-install/SKILL.md
- skill skynetcmd-m3-memory-a9d2161/.antigravity-plugin/skills/m3-notify/SKILL.md
- skill skynetcmd-m3-memory-a9d2161/.antigravity-plugin/skills/m3-save/SKILL.md
- skill skynetcmd-m3-memory-a9d2161/.antigravity-plugin/skills/m3-search/SKILL.md
- skill skynetcmd-m3-memory-a9d2161/.antigravity-plugin/skills/m3-status/SKILL.md
- skill skynetcmd-m3-memory-a9d2161/.antigravity-plugin/skills/m3-tasks/SKILL.md
- skill skynetcmd-m3-memory-a9d2161/.antigravity-plugin/skills/m3-write/SKILL.md
- agent-rules skynetcmd-m3-memory-a9d2161/AGENTS.md
- agent-rules skynetcmd-m3-memory-a9d2161/CLAUDE.md
- agent-rules skynetcmd-m3-memory-a9d2161/GEMINI.md
- agent-rules skynetcmd-m3-memory-a9d2161/commands/agents.md
- agent-rules skynetcmd-m3-memory-a9d2161/docs/AGENTS.md
- skill skynetcmd-m3-memory-a9d2161/skills/m3-guide/SKILL.md
danger signals9
- dynamic code execution eval()/exec() skynetcmd-m3-memory-a9d2161/bin/memory_bridge.py :239
exec(src, ns) # nosec B102 - src is built from static ToolSpec catalog, not user input - dynamic code execution eval()/exec() skynetcmd-m3-memory-a9d2161/m3_memory/cli.py :200
exec(code, {"__file__": str(bridge), "__name__": "__main__"}) # nosec B102 - dynamic code execution __import__() skynetcmd-m3-memory-a9d2161/m3_memory/cli.py :601
__import__(mod) - dynamic code execution __import__() skynetcmd-m3-memory-a9d2161/m3_memory/installer.py :754
__import__(mod) - dynamic code execution __import__() skynetcmd-m3-memory-a9d2161/m3_memory/setup_wizard.py :2488
__import__(mod) - dynamic code execution __import__ sink skynetcmd-m3-memory-a9d2161/tests/test_fips_aes_context_size.py :83
env={**__import__("os").environ, - committed secret Anthropic key skynetcmd-m3-memory-a9d2161/bin/chatlog_redaction.py :346
sk-ant…(33 chars, redacted) - committed secret Anthropic key skynetcmd-m3-memory-a9d2161/tests/bench_oxidation.py :368
sk-ant…(49 chars, redacted) - committed secret Anthropic key skynetcmd-m3-memory-a9d2161/tests/test_redaction_parity.py :59
sk-ant…(49 chars, redacted)
- recent drift +20 capability drift →
Heuristic, inferred signals — false positives (legitimately powerful tools, forks, language ports) are expected. Treat each as "review this", not a verdict. See the ecosystem-wide picture on the security hub, or the fleet security of skynetcmd.