klh-project-memory
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow where the agent is instructed to proactively read and follow protocols stored in project documentation files. This creates a surface where instructions embedded in those files (e.g., from external contributions) could influence the agent's logic.
- Ingestion points: Reads files in
docs/project_notes/(bugs.md,decisions.md,key_facts.md,issues.md) and configuration files likeCLAUDE.mdandAGENTS.md. - Boundary markers: The skill uses templates and markdown headers to structure data, but does not implement explicit delimiters or 'ignore' instructions for the data it processes.
- Capability inventory: The skill uses standard file system access (reading and writing via agent tools) and the shell
greputility. - Sanitization: Content is written based on user input or bug resolution notes; no specific sanitization logic is described for the content written to the memory logs.
- [COMMAND_EXECUTION]: The skill utilizes the
grepcommand to search through project documentation for specific terms, such as error messages or previous architectural decisions. This is a standard search functionality within the documented scope of the skill. - [EXTERNAL_DOWNLOADS]: The project documentation references external installation methods via the
skilzCLI and vendor-owned GitHub repositories. These are standard software distribution patterns and are not executed dynamically by the skill at runtime.
Audit Metadata