nd-working-memory
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill implements organizational patterns designed to reduce cognitive load by explicitly tracking task states and goals. The instructions are transparent and do not attempt to bypass safety filters or execute unauthorized commands.- [PROMPT_INJECTION]: The skill interacts with repository data (task files, roadmaps, ledgers), which represents a standard surface for indirect prompt injection. This usage is evaluated as safe given the skill's purpose as an organizational anchor.
- Ingestion points: Repository files, conversation history, task files, and saved ledgers.
- Boundary markers: The skill encourages a structured constraint ledger (using fields like 'Must:', 'Must not:', and 'Task:') to isolate task context.
- Capability inventory: The skill is authorized to read from the repository and update existing project task/roadmap files.
- Sanitization: No explicit content sanitization is described beyond the use of structured headers to orient the agent.
Audit Metadata