AgentScore is for sale. View the assets and acquisition details →
low

AGENTSCORE-2026-0102

MCP package: memorix

Published 8/13/2026 · 1.4.2 → 1.4.3

Automated, not yet reviewed

This advisory was generated automatically by a pattern-matching scanner when the package's score changed. Its findings have not been checked in the package source yet. Pattern matching produces false positives: when automated command-injection findings were first reviewed in source, most were not exploitable. Treat unreviewed findings as leads, not verdicts.

memorix updated from 1.4.2 to 1.4.3. Score changed 85/100 to 80/100 (-5). Risk: LOW to MODERATE. 3 findings.

85 → 80
Score
LOW → MODERATE
Risk
ALLOW
Verdict

Findings

  • medium excessive_dependencies: Package has 23 runtime dependencies (high attack surface)
  • low command_injection: Potential command injection: shell execution with template literal input (downgraded — mitigators detected in scope: sanitizer:.exec(`BEGIN, test_fixture:test()
  • low no_provenance: Package is not published with provenance attestations or trusted publishing. Published by: avids2