klh-project-memory

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow where the agent is instructed to proactively read and follow protocols stored in project documentation files. This creates a surface where instructions embedded in those files (e.g., from external contributions) could influence the agent's logic.
  • Ingestion points: Reads files in docs/project_notes/ (bugs.md, decisions.md, key_facts.md, issues.md) and configuration files like CLAUDE.md and AGENTS.md.
  • Boundary markers: The skill uses templates and markdown headers to structure data, but does not implement explicit delimiters or 'ignore' instructions for the data it processes.
  • Capability inventory: The skill uses standard file system access (reading and writing via agent tools) and the shell grep utility.
  • Sanitization: Content is written based on user input or bug resolution notes; no specific sanitization logic is described for the content written to the memory logs.
  • [COMMAND_EXECUTION]: The skill utilizes the grep command to search through project documentation for specific terms, such as error messages or previous architectural decisions. This is a standard search functionality within the documented scope of the skill.
  • [EXTERNAL_DOWNLOADS]: The project documentation references external installation methods via the skilz CLI and vendor-owned GitHub repositories. These are standard software distribution patterns and are not executed dynamically by the skill at runtime.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 10:41 AM
Security Audit — agent-trust-hub — klh-project-memory