memory-bridge
Pass
Audited by Gen Agent Trust Hub on Oct 6, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
rg(ripgrep) to search within a specific subset of files defined by the manifest metadata. The input is taken from the user's search topic and is executed within the scope of the local vault directory. - [DATA_EXPOSURE]: The skill accesses the Obsidian vault path, specifically
.manifest.json,index.md, and individual markdown pages. This access is required for the stated purpose of browsing and comparing wiki knowledge. The results are presented to the user and logged locally inlog.mdwithin the vault. - [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied wiki content and manifest data. While there is a risk of instructions being embedded in these files, the skill's capabilities are limited to reading, searching, and logging within the local vault, which significantly mitigates the impact of such injections. The skill explicitly instructs the agent to avoid reading full page bodies when metadata greps suffice, further reducing the surface area.
Audit Metadata