memory-system
Fail
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: HIGHCREDENTIALS_UNSAFEPRIVILEGE_ESCALATIONPERSISTENCECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill accesses a sensitive configuration file located at
~/.config/system-bus.env, which is documented to contain a signing key. - [PRIVILEGE_ESCALATION]: The instructions require the use of
sudofor steering the shutdown process of parked services (Chorus/Rhizomatic). - [PERSISTENCE]: The skill relies on and manages multiple macOS LaunchAgents (
com.joelclaw.observer-tick,com.joelclaw.observer-dream,com.joelclaw.observer-neat-memory) to maintain execution across sessions and perform background tasks. - [COMMAND_EXECUTION]: The skill frequently executes shell commands and scripts for deployment and debugging, including
bash ~/.joelclaw/observer-release/bin/neat-memory.shandbin/promote-release.sh, and relies on tools likebun,jq, andlaunchctl. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data from observation pages and retros to populate its 'Brain' and curator state, which could be exploited to influence agent behavior.
- Ingestion points: Observation pages in
~/Code/joelhooks/dark-wizard/.brain/observations/and retro files in.brain/resources/retros/. - Boundary markers: No explicit delimiters or boundary markers are defined to isolate data from instructions.
- Capability inventory: The system has extensive capabilities including file system modification, shell command execution, and external messaging via Telegram.
- Sanitization: No sanitization or validation logic is mentioned for the ingested memory content.
Recommendations
- AI detected serious security threats
Audit Metadata