hindsight
Pass
Audited by Gen Agent Trust Hub on Jun 23, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: Downloads official CLI tools and integrations from vendor-controlled domains and package registries.
- [REMOTE_CODE_EXECUTION]: Provides instructions for installing the Hindsight memory system through piped shell scripts from official vendor endpoints.
- [COMMAND_EXECUTION]: Uses the hindsight CLI binary to manage memory banks and perform semantic retrieval operations.
- [DATA_EXFILTRATION]: Accesses local configuration files (~/.openclaw/openclaw.json) to validate memory governance settings; no unauthorized external transmission of sensitive data was observed.
- [PROMPT_INJECTION]: Implements a persistent memory architecture that ingests external conversational data and interpolates it into agent prompts. Boundary markers like hindsight_memories tags are used in integration plugins to scope the context. Sanitization routines are present to strip tags before re-storage to prevent recursive injection loops.
Audit Metadata