episodic-archiver

Pass

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill frequently invokes other local skills and utilities via subprocess calls to perform its operations.
  • memory_helpers.py and analysis_integrations.py execute memory/run.sh to store lessons and recall data.
  • analysis_integrations.py executes dogpile/run.sh to research technical gaps identified during session analysis.
  • archive_episode.py invokes edge-verifier/run.sh for session verification.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it processes untrusted conversation transcripts to drive agent behavior and tool usage.
  • Ingestion points: Reads .jsonl and .json transcript files from configured local source paths (e.g., ~/.claude/projects, ~/.codex/sessions) in run.sh and archive_episode.py.
  • Boundary markers: Prompts in analysis_llm.py (e.g., assess_session and profile_user_from_session) interpolate transcript content without strong delimiters or specific instructions to ignore embedded commands.
  • Capability inventory: The skill can execute subprocesses, write to ArangoDB, and trigger external research tasks via the dogpile skill based on the output of its analysis.
  • Sanitization: While the skill uses list-based subprocess.run calls to prevent direct shell injection, it does not sanitize the semantic content extracted from transcripts before passing it to subsequent LLM prompts or tool parameters.
  • [EXTERNAL_DOWNLOADS]: The skill specifies dependencies from the author's GitHub repositories in pyproject.toml.
  • Fetches graph-memory from github.com/grahama1970/graph-memory-operator.git.
  • Fetches scillm from github.com/grahama1970/scillm.git.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 17, 2026, 06:35 AM
Security Audit — agent-trust-hub — episodic-archiver