skills/klh/skills/klh-project-memory/Gen Agent Trust Hub

klh-project-memory

Pass

Audited by Gen Agent Trust Hub on Jun 19, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's primary function is to manage project documentation and institutional knowledge using local markdown files within the docs/project_notes/ directory.
  • [DATA_EXPOSURE]: The skill incorporates comprehensive security warnings in both the documentation and the templates (e.g., key_facts_template.md). It explicitly instructs users and the AI agent never to store sensitive credentials such as API keys, passwords, or private keys in the memory files, recommending safe alternatives like .env files and dedicated secret managers.
  • [COMMAND_EXECUTION]: The skill instructions guide the agent to use standard shell commands (e.g., grep, mkdir, cp) for managing and searching local documentation files. These operations are limited to the project directory and align with the skill's documented purpose.
  • [INDIRECT_PROMPT_INJECTION]: While the skill establishes a mechanism for the agent to read external project data (which is a common surface for indirect prompt injection), it mitigates risk by providing structured templates and clear protocols in CLAUDE.md and AGENTS.md for how this data should be processed and maintained.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 19, 2026, 11:49 AM
Security Audit — agent-trust-hub — klh-project-memory