reflect-memory

Pass

Audited by Gen Agent Trust Hub on Jul 27, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill processes external files such as AGENTS.md and CLAUDE.md which act as ingestion points for data that could contain indirect prompt injections. The agent is instructed to read and modify these files based on their content.
  • Ingestion points: AGENTS.md, CLAUDE.md, .reflect/observations.md, .reflect/applied.md.
  • Boundary markers: The skill does not define specific delimiters or instructions to ignore embedded prompts within these files.
  • Capability inventory: The agent has the ability to read and overwrite the targeted configuration files.
  • Sanitization: The skill relies on mechanical checks and user proposals but lacks automated sanitization for potentially malicious content in the instructions.
  • [DATA_EXPOSURE]: The skill accesses the ~/.reflect/ directory. This is a vendor-specific hidden directory in the user's home folder used for state management and historical observations.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 27, 2026, 03:07 AM
Security Audit — agent-trust-hub — reflect-memory