agent-memory
Pass
Audited by Gen Agent Trust Hub on Aug 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill implements a persistent memory system that stores arbitrary project context, research findings, and architectural decisions, creating a surface for indirect prompt injection. \n
- Ingestion points: The skill instructions in
SKILL.mddirect the agent to proactively save findings, solutions, and patterns discovered during work. \n - Boundary markers: Memory files lack specific delimiters or instructions to ignore embedded malicious content. \n
- Capability inventory: The skill utilizes shell commands like
ls,rg,mkdir,cat,trash, andrmdirfor file management. \n - Sanitization: No sanitization or validation of the ingested content is performed before saving to the local filesystem.\n- [COMMAND_EXECUTION]: The skill documentation in
SKILL.mdinstructs the agent to execute multiple shell commands for memory management, includingls,ripgrep,mkdir,cat,trash, andrmdir. While restricted to a specific local directory, this grants the agent broad filesystem interaction capabilities.\n- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill encourages proactive storage of sensitive project context, including architectural decisions and research findings, in a local directory (.claude/skills/agent-memory/memories/). This creates a risk of data exposure if the workspace environment is shared or compromised.\n- [METADATA_POISONING]: Theskill-report.jsonfile contains self-referential security audit claims and safety declarations (e.g., 'Safe to publish'), which is a pattern that can be used to influence automated security analysis tools.
Audit Metadata