claude-mem
Warn
Audited by Gen Agent Trust Hub on Apr 8, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill uses npx to download and install its core components from the NPM registry.
- [COMMAND_EXECUTION]: Configures multiple lifecycle hooks that automatically execute code during agent startup, tool usage, and shutdown.
- [DATA_EXFILTRATION]: Systematically records all tool inputs and outputs, creating a repository of potentially sensitive user and system information.
- [PROMPT_INJECTION]: Subject to indirect prompt injection through the automated re-injection of past context.
- Ingestion points: Tool activity across all sessions (SKILL.md).
- Boundary markers: Absent.
- Capability inventory: Bash, Read, and Write tools (SKILL.md).
- Sanitization: Not performed on captured data.
Audit Metadata