← All tools

MemPalace

AI Assistant
D
Overall score: 1.9Reviewed April 15, 2026

Genuinely local-first and MIT-licensed, but the provided official website is inaccessible or an impostor, no ToS or Privacy Policy exists anywhere, a shell injection vulnerability in the hooks was only partially patched, and the launch benchmark claims were materially false before a public correction.

Score Summary

Claim Accuracy2/5
Data & Privacy1/5
Security Posture2/5
Transparency3/5

Key Findings

  • The website URL provided (mempalaceofficial.com) returned a 403 error and may be an impostor site — the MemPalace/mempalace README explicitly states 'MemPalace has no website (at least for now), so anything claiming to be one is false' (source: github.com/MemPalace/mempalace README).
  • No Terms of Service or Privacy Policy exists for MemPalace in any official location — there are no legal protections, data commitments, or user rights documented anywhere (source: exhaustive search of mempalaceofficial.com, github.com/milla-jovovich/mempalace, github.com/MemPalace/mempalace).
  • A shell injection vulnerability in the bash save hooks (Issue #110) was publicly acknowledged in the README and partially addressed — the later release changelog (#387) confirms 'shell-injection fix in save hook' but the original v3.0.0 release shipped with the vulnerability present (source: github.com/milla-jovovich/mempalace README, github.com/MemPalace/mempalace/releases).
  • The launch benchmark claim of 100% on LongMemEval was materially false — the team issued a detailed public correction within 48 hours downgrading to 96.6% in raw mode, retracting the '30x lossless compression' AAAK claim, the '+34% palace boost' framing, and acknowledging contradiction detection was not wired into the product as implied (source: github.com/milla-jovovich/mempalace README, 'A Note from Milla and Ben — April 7, 2026').
  • The project launched April 6, 2026 — approximately 9 days old at review time — with one versioned release (v3.0.0), 77 open issues, and active but unproven maintenance; no enterprise adoption beyond a single informal deployment by a known AI commentator has been documented (source: github.com/milla-jovovich/mempalace).