project-memory-workflow

Pass

Audited by Gen Agent Trust Hub on Apr 24, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill defines a structured workflow for maintaining project memory using local files in the .kavion/ directory. No network-based exfiltration or unauthorized file access patterns were detected.
  • [SAFE]: Includes specific hygiene rules that prohibit storing credentials, secrets, or PII in memory files, which reduces the risk of accidental data exposure.
  • [SAFE]: While the skill reads and processes user-controlled project files (Ingestion points: .kavion/ directory files; Boundary markers: Absent; Capability inventory: File modification and search index rebuilding; Sanitization: Absent), this is necessary for its core function and is mitigated by the safety rules and the vendor-specific scope.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 24, 2026, 08:06 PM
Security Audit — agent-trust-hub — project-memory-workflow