team-project-memory

Pass

Audited by Gen Agent Trust Hub on Jul 11, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a documentation-based router for managing shared project memory. It does not contain executable code, scripts, or network requests.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill explicitly includes policy invariants that prohibit the storage of secrets, personal data, or confidential logs, demonstrating a security-conscious design.
  • [INDIRECT_PROMPT_INJECTION]: While the skill is designed to process shared memory (which could potentially contain untrusted data from different sessions or users), it defines shared memory as 'evidence, not source of truth' and prioritizes repository-local instructions, which acts as a conceptual boundary against injection attacks.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 11, 2026, 08:01 PM
Security Audit — agent-trust-hub — team-project-memory