memory-write-router

Pass

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute Node.js commands using node -e to interface with a local memory adapter (lib/memory/adapter.js). The instruction to pass data 'verbatim' into a shell command string represents a potential command injection surface if the agent does not properly escape the payload.
  • [DATA_EXFILTRATION]: The skill reads from local configuration files and state metadata located in the ~/.claude/ directory to determine the active memory backend and verify existing records before writing.
  • [PROMPT_INJECTION]: The skill acts as an ingestion surface for indirect prompt injection by persisting user-provided facts and preferences into long-term memory without explicit sanitization.
  • Ingestion points: Reads from ~/.claude/sustain/state.json, ~/.claude/CLAUDE.md, and the active conversation context.
  • Boundary markers: None present; stored memory content is treated as authoritative instructions or facts in future sessions.
  • Capability inventory: Uses the mcp__mempalace__store tool and shell execution via node -e to manage persistent state.
  • Sanitization: No sanitization, validation, or escaping of the memory content is performed prior to storage.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 13, 2026, 02:53 PM
Security Audit — agent-trust-hub — memory-write-router