memory-bridge

Pass

Audited by Gen Agent Trust Hub on Oct 6, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses rg (ripgrep) to search within a specific subset of files defined by the manifest metadata. The input is taken from the user's search topic and is executed within the scope of the local vault directory.
  • [DATA_EXPOSURE]: The skill accesses the Obsidian vault path, specifically .manifest.json, index.md, and individual markdown pages. This access is required for the stated purpose of browsing and comparing wiki knowledge. The results are presented to the user and logged locally in log.md within the vault.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied wiki content and manifest data. While there is a risk of instructions being embedded in these files, the skill's capabilities are limited to reading, searching, and logging within the local vault, which significantly mitigates the impact of such injections. The skill explicitly instructs the agent to avoid reading full page bodies when metadata greps suffice, further reducing the surface area.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 6, 2026, 01:26 AM