memory-management
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches the
claude-repo-memPython package from a public registry and downloads an embedding model (BAAI/bge-small-en-v1.5) from a well-known machine learning repository during the indexing process. - [COMMAND_EXECUTION]: Executes several subcommands of the
claude-repo-memutility, includingindexto build the repository map,serveto launch the MCP server, anddistillto process transcripts. It also modifies the repository configuration by optionally installing a gitpost-commithook. - [DATA_EXFILTRATION]: The skill is designed to read and process the entire target repository, including source code and documentation, to build a local vector index. It also accesses Claude Code session transcripts stored in
~/.claude/projects/to extract and persist durable project decisions. - [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it processes untrusted data from the repository and interaction logs.
- Ingestion points: The indexing process (
claude-repo-mem index) reads every file within the target repository workspace, and thedistillcommand reads external transcript files. - Boundary markers: No specific delimiters or "ignore instructions" markers are defined for the data retrieved from the index.
- Capability inventory: The skill exposes 11 tools (e.g.,
recall,trace,expand) that return indexed content directly to the agent's context. - Sanitization: No explicit sanitization or filtering of the content retrieved from the repository or transcripts is performed before it is presented to the model.
Audit Metadata