brain-save
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and persist user-provided facts and architectural decisions. While this data could potentially influence future agent behavior if it contains malicious instructions, the risk is significantly mitigated by the skill's design: \n
- Ingestion points: Untrusted data enters the system through the
brain_capturetool as specified in theSKILL.mdinstructions and thereferences/runtime-contract.md. \n - Boundary markers: The skill relies on structured tool parameters for data intake rather than raw prompt interpolation. Furthermore, the
disable-model-invocation: trueconfiguration prevents the skill from being triggered automatically by potentially malicious conversation content. \n - Capability inventory: The tools provided (
brain_search,brain_capture,brain_govern,brain_transition,brain_status,brain_audit_verify) are strictly limited to the scope of memory management, governance, and auditing. \n - Sanitization: The
brain_governtool enforces deterministic policies, including deduplication and secret detection. The skill also includes explicit instructions for users to strip credentials before capture. \n- [EXTERNAL_DOWNLOADS]: The documentation references thegoverned-second-brainplugin hosted athttps://github.com/jeremylongshore/bobs-big-brain-plugin. This repository is a vendor-owned resource belonging to the skill's author and is required for the skill's core functionality. \n- [SAFE]: The skill follows security best practices by implementing an audit trail with SHA-256 hash chains and providing a specific verification tool (brain_audit_verify) to detect tampering or migration issues in the local memory store.
Audit Metadata