memory-search-bridge
Pass
Audited by Gen Agent Trust Hub on Jun 13, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection attacks because it retrieves and processes content from external memory files and user documents without protection.
- Ingestion points: Data is read from
~/.claude/sustain/memory/,~/.claude/projects/<project>/memory/MEMORY.md, and~/Documents/AI/. - Boundary markers: No delimiters or "ignore instructions" warnings are provided to the agent to distinguish data from instructions.
- Capability inventory: The skill utilizes shell commands (
grep), MCP tools, and a local JavaScript adapter for file system interaction. - Sanitization: No sanitization or validation of the retrieved content is defined in the instructions.
- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands, specifically
grep, to perform searches on the local file system using keyword input.
Audit Metadata