klh-project-memory
Pass
Audited by Gen Agent Trust Hub on Jun 19, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill's primary function is to manage project documentation and institutional knowledge using local markdown files within the
docs/project_notes/directory. - [DATA_EXPOSURE]: The skill incorporates comprehensive security warnings in both the documentation and the templates (e.g.,
key_facts_template.md). It explicitly instructs users and the AI agent never to store sensitive credentials such as API keys, passwords, or private keys in the memory files, recommending safe alternatives like.envfiles and dedicated secret managers. - [COMMAND_EXECUTION]: The skill instructions guide the agent to use standard shell commands (e.g.,
grep,mkdir,cp) for managing and searching local documentation files. These operations are limited to the project directory and align with the skill's documented purpose. - [INDIRECT_PROMPT_INJECTION]: While the skill establishes a mechanism for the agent to read external project data (which is a common surface for indirect prompt injection), it mitigates risk by providing structured templates and clear protocols in
CLAUDE.mdandAGENTS.mdfor how this data should be processed and maintained.
Audit Metadata