bm-orient

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill performs standard configuration resolution by reading settings from ~/.claude/settings.json and project-specific .claude/settings.json files. These operations are restricted to the author's defined Basic Memory ecosystem tools and parameters.
  • [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it ingests and summarizes data from the search_notes tool. This is a functional requirement for the skill's purpose and is handled with appropriate scoping to specific projects.
  • Ingestion points: Results from the search_notes tool described in SKILL.md.
  • Boundary markers: None specified in the instructions.
  • Capability inventory: Read-only access to configuration files and execution of searching tools.
  • Sanitization: None specified.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 02:04 AM
Security Audit — agent-trust-hub — bm-orient