episodic-archiver
Pass
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill frequently invokes other local skills and utilities via subprocess calls to perform its operations.
memory_helpers.pyandanalysis_integrations.pyexecutememory/run.shto store lessons and recall data.analysis_integrations.pyexecutesdogpile/run.shto research technical gaps identified during session analysis.archive_episode.pyinvokesedge-verifier/run.shfor session verification.- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it processes untrusted conversation transcripts to drive agent behavior and tool usage.
- Ingestion points: Reads
.jsonland.jsontranscript files from configured local source paths (e.g.,~/.claude/projects,~/.codex/sessions) inrun.shandarchive_episode.py. - Boundary markers: Prompts in
analysis_llm.py(e.g.,assess_sessionandprofile_user_from_session) interpolate transcript content without strong delimiters or specific instructions to ignore embedded commands. - Capability inventory: The skill can execute subprocesses, write to ArangoDB, and trigger external research tasks via the
dogpileskill based on the output of its analysis. - Sanitization: While the skill uses list-based
subprocess.runcalls to prevent direct shell injection, it does not sanitize the semantic content extracted from transcripts before passing it to subsequent LLM prompts or tool parameters. - [EXTERNAL_DOWNLOADS]: The skill specifies dependencies from the author's GitHub repositories in
pyproject.toml. - Fetches
graph-memoryfromgithub.com/grahama1970/graph-memory-operator.git. - Fetches
scillmfromgithub.com/grahama1970/scillm.git.
Audit Metadata