memory-management

Pass

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill operates entirely within the local file system using 'CLAUDE.md' and a 'memory/' directory. No network exfiltration, credential theft, or external script execution was detected.
  • [PROMPT_INJECTION]: The memory system creates an indirect prompt injection surface by storing and recalling context from external sources. 1. Ingestion points: 'CLAUDE.md' and files within the 'memory/' directory. 2. Boundary markers: Data is structured using Markdown tables and headers but lacks explicit 'ignore instructions' delimiters for untrusted input. 3. Capability inventory: The skill provides instructions for the agent to perform read and write operations on the local file system. 4. Sanitization: No evidence of validation or sanitization of ingested content before storage or recall was found.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 10, 2026, 12:22 PM
Security Audit — agent-trust-hub — memory-management