memory-management

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches the claude-repo-mem Python package from a public registry and downloads an embedding model (BAAI/bge-small-en-v1.5) from a well-known machine learning repository during the indexing process.
  • [COMMAND_EXECUTION]: Executes several subcommands of the claude-repo-mem utility, including index to build the repository map, serve to launch the MCP server, and distill to process transcripts. It also modifies the repository configuration by optionally installing a git post-commit hook.
  • [DATA_EXFILTRATION]: The skill is designed to read and process the entire target repository, including source code and documentation, to build a local vector index. It also accesses Claude Code session transcripts stored in ~/.claude/projects/ to extract and persist durable project decisions.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it processes untrusted data from the repository and interaction logs.
  • Ingestion points: The indexing process (claude-repo-mem index) reads every file within the target repository workspace, and the distill command reads external transcript files.
  • Boundary markers: No specific delimiters or "ignore instructions" markers are defined for the data retrieved from the index.
  • Capability inventory: The skill exposes 11 tools (e.g., recall, trace, expand) that return indexed content directly to the agent's context.
  • Sanitization: No explicit sanitization or filtering of the content retrieved from the repository or transcripts is performed before it is presented to the model.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 08:35 AM
Security Audit — agent-trust-hub — memory-management