memory-optimize
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests auto-memory files (~/.claude/projects/**/memory/*.md) which contain context from past interactions and external sources. This data is untrusted and could be used to inject instructions aimed at the agent's file-management logic.
- Ingestion points: Scans memory files, CLAUDE.md files, and rule files from project and global directories.
- Boundary markers: The skill does not employ specific delimiters or boundary instructions to isolate untrusted content during analysis.
- Capability inventory: The skill has extensive permissions to read, write, and edit local files, and to execute shell commands via Bash.
- Sanitization: The skill incorporates a mandatory human review step using the AskUserQuestion tool before any destructive actions or file changes are executed.
- [COMMAND_EXECUTION]: The skill frontmatter includes access to the Bash tool. While the workflow utilizes this for context discovery and file operations, providing a full shell environment increases the potential impact if the agent is influenced by malicious content in memory files.
- [EXTERNAL_DOWNLOADS]: The README provides installation instructions using npx and references to a GitHub repository (github.com/kochetkov-ma/claude-brewcode). These resources are tied to the skill's author and reflect standard installation practices within the platform's ecosystem.
Audit Metadata