memory-management
Pass
Audited by Gen Agent Trust Hub on Jul 10, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill operates entirely within the local file system using 'CLAUDE.md' and a 'memory/' directory. No network exfiltration, credential theft, or external script execution was detected.
- [PROMPT_INJECTION]: The memory system creates an indirect prompt injection surface by storing and recalling context from external sources. 1. Ingestion points: 'CLAUDE.md' and files within the 'memory/' directory. 2. Boundary markers: Data is structured using Markdown tables and headers but lacks explicit 'ignore instructions' delimiters for untrusted input. 3. Capability inventory: The skill provides instructions for the agent to perform read and write operations on the local file system. 4. Sanitization: No evidence of validation or sanitization of ingested content before storage or recall was found.
Audit Metadata