manage-knowhow
Pass
Audited by Gen Agent Trust Hub on Jul 3, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill's functionality is consistent with its stated purpose of managing local memory files. It includes robust safety invariants such as protected files (MEMORY.md), mandatory user confirmation for deletions, and dry-run modes for pruning operations.
- [COMMAND_EXECUTION]: Shell command usage is limited to standard search utilities (grep) and local environment tools (maestro), which are used for searching and listing entries within the defined project scope. These operations are restricted to relevant memory directories.
- [DATA_EXFILTRATION]: Access is restricted to specific project-related directories (.workflow/knowhow/ and ~/.claude/projects/*/memory/). There is no evidence of unauthorized sensitive data access or transmission to external domains.
Audit Metadata