memory-management

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill operates as a localized developer utility, managing and organizing project-specific instructions and learned patterns without external risks.
  • [DATA_EXPOSURE]: The skill processes local memory and configuration files to provide curation insights. It explicitly documents the storage of credentials in these files as an anti-pattern.
  • [COMMAND_EXECUTION]: Implements a platform-native error-capture hook (PostToolUse) to monitor for shell failures and prompt the user to capture solutions. This is a standard productivity feature and does not execute unauthorized commands.
  • [PROMPT_INJECTION]: The skill processes auto-memory data that may originate from untrusted external sources and provides a workflow to promote this data into permanent project rules. Ingestion points: Reads project memory files from ~/.claude/projects/*/memory/. Boundary markers: No explicit delimiters are specified for memory entries. Capability inventory: Ability to write to project-wide instructions (CLAUDE.md, .claude/rules/) and generate new skill definitions (SKILL.md). Sanitization: Employs quality checks in the extraction sub-agent to ensure generated content is portable and adheres to size limits.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 03:11 PM
Security Audit — agent-trust-hub — memory-management