agent-memory

Pass

Audited by Gen Agent Trust Hub on Aug 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill implements a persistent memory system that stores arbitrary project context, research findings, and architectural decisions, creating a surface for indirect prompt injection. \n
  • Ingestion points: The skill instructions in SKILL.md direct the agent to proactively save findings, solutions, and patterns discovered during work. \n
  • Boundary markers: Memory files lack specific delimiters or instructions to ignore embedded malicious content. \n
  • Capability inventory: The skill utilizes shell commands like ls, rg, mkdir, cat, trash, and rmdir for file management. \n
  • Sanitization: No sanitization or validation of the ingested content is performed before saving to the local filesystem.\n- [COMMAND_EXECUTION]: The skill documentation in SKILL.md instructs the agent to execute multiple shell commands for memory management, including ls, ripgrep, mkdir, cat, trash, and rmdir. While restricted to a specific local directory, this grants the agent broad filesystem interaction capabilities.\n- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill encourages proactive storage of sensitive project context, including architectural decisions and research findings, in a local directory (.claude/skills/agent-memory/memories/). This creates a risk of data exposure if the workspace environment is shared or compromised.\n- [METADATA_POISONING]: The skill-report.json file contains self-referential security audit claims and safety declarations (e.g., 'Safe to publish'), which is a pattern that can be used to influence automated security analysis tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 23, 2026, 12:39 AM