Skip to content

Agent-driven install flow wires credentialed integrations into 6 hosts with no per-host consent step #14

Description

@LCS-Dev-Ergos

Summary

While auditing my machine, I found that EverMe had been installed and configured across six different AI-agent hosts — Claude Code, Cursor, Codex, Devin, Hermes, and Claude Desktop — via evercli. Each install wrote a live evt_* agent token to disk (in ~/.claude/everme.env, ~/.cursor/mcp.json, ~/.codex/config.toml, ~/.config/devin/mcp_config.json, ~/.hermes/config.yaml, and Claude Desktop's claude_desktop_config.json), and several also registered lifecycle hooks that invoke npx -y @everme/cursor@latest hook ... (and the equivalent for other hosts) on every session start/stop/tool-use.

I don't have a record of separately and knowingly approving each of these six installs. Reading the README, the intended flow appears to be: an AI agent is given the one-line instruction "Read https://everme.evermind.ai/SKILL.md and follow the instruction to install and configure EverMe", after which the agent installs the CLI, authenticates, and "registers the plugin for itself." That's a powerful pattern — any agent told to follow that URL (from a README, a chat message, a shared doc, etc.) can install a credentialed, cross-tool memory-sync integration across every AI-agent host it finds on the machine, with no visible per-host confirmation step in the flow itself.

Requests

  1. Consider adding an explicit, visible per-host confirmation step to the agent-driven install flow (today only evercli auth login is a clear user-facing checkpoint; each subsequent plugin install <host> is not).
  2. Document a single, authoritative uninstall path that removes all host integrations and env files in one step. Today, fully removing EverMe requires manually finding and reversing changes across six different config locations.
  3. I attempted to delete my account data via the EverMe product/web portal and the deletion did not complete. I've separately emailed legal@evermind.ai (per the published Privacy Policy) with a formal erasure request, flagging it here too since the self-service path itself appears broken and other users may hit the same issue.

No evt_*/emk_* values are included in this report, per SECURITY.md. Happy to provide further (redacted) detail if useful.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions