skills/johnlindquist/claude/memory/Gen Agent Trust Hub

memory

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the basic-memory Python package from PyPI. This is a standard dependency for the skill's stated purpose.- [COMMAND_EXECUTION]: The skill operates by executing various subcommands of the basic-memory CLI tool (e.g., write-note, read-note, search-notes, build-context). This is the intended behavior for interfacing with the memory system.- [DATA_EXFILTRATION]: The basic-memory sync command implies network activity to synchronize the local memory database with a remote service. While this is expected for a 'sync' feature, users should be aware that their stored notes may be transmitted externally.- [INDIRECT_PROMPT_INJECTION]: The skill retrieves previously stored notes to build context for the agent. If a note contains malicious instructions (e.g., injected by a third party or a previous malicious input), the agent might follow those instructions when the note is loaded back into its active context.
  • Ingestion points: Notes are retrieved via read-note, search-notes, and build-context in SKILL.md.
  • Boundary markers: No explicit boundary markers or 'ignore' instructions are defined to separate note content from system instructions.
  • Capability inventory: The agent can execute shell commands, read files, and write files as part of its normal operation.
  • Sanitization: There is no evidence of sanitization or filtering of the note content before it is interpolated into the agent's prompt.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 08:25 PM
Security Audit — agent-trust-hub — memory