project-memory

Pass

Audited by Gen Agent Trust Hub on Jun 24, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The skill introduces a surface for indirect prompt injection (Category 8) by instructing the agent to trust and automatically apply "known solutions" from project documentation.
  • Ingestion points: The agent is instructed to read content from docs/project_notes/bugs.md and docs/project_notes/decisions.md before proposing architectural changes or fixing errors.
  • Boundary markers: No specific delimiters or "ignore embedded instructions" warnings are suggested for these files in the CLAUDE.md or SKILL.md protocols.
  • Capability inventory: The agent has full capabilities to modify the codebase, execute commands, and manage infrastructure based on the advice found in these memory files.
  • Sanitization: The skill lacks instructions for validating or sanitizing the content of the memory files before the agent acts on them, which could lead to the execution of malicious code if the files are poisoned (e.g., via a malicious Pull Request).
  • [DATA_EXFILTRATION]: The skill encourages centralizing project configuration in docs/project_notes/key_facts.md, which is intended to be committed to version control.
  • Exposure Risk: While the skill provides extensive warnings and templates (e.g., in references/key_facts_template.md) about NOT storing secrets, the SKILL.md instructions explicitly list "credentials" as a target for storage and searching in this file. This terminology may lead users to inadvertently document sensitive authentication tokens or passwords that could then be exposed or exfiltrated if the agent context is compromised.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 24, 2026, 12:49 PM
Security Audit — agent-trust-hub — project-memory