memory-write-router
Pass
Audited by Gen Agent Trust Hub on Jun 13, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute Node.js commands using
node -eto interface with a local memory adapter (lib/memory/adapter.js). The instruction to pass data 'verbatim' into a shell command string represents a potential command injection surface if the agent does not properly escape the payload. - [DATA_EXFILTRATION]: The skill reads from local configuration files and state metadata located in the
~/.claude/directory to determine the active memory backend and verify existing records before writing. - [PROMPT_INJECTION]: The skill acts as an ingestion surface for indirect prompt injection by persisting user-provided facts and preferences into long-term memory without explicit sanitization.
- Ingestion points: Reads from
~/.claude/sustain/state.json,~/.claude/CLAUDE.md, and the active conversation context. - Boundary markers: None present; stored memory content is treated as authoritative instructions or facts in future sessions.
- Capability inventory: Uses the
mcp__mempalace__storetool and shell execution vianode -eto manage persistent state. - Sanitization: No sanitization, validation, or escaping of the memory content is performed prior to storage.
Audit Metadata