awake

Pass

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes shell commands using project-specific tools, notably the mempalace CLI (e.g., mempalace wake-up). These tools are identified as resources associated with the vendor (Oruga420).
  • [PROMPT_INJECTION]: The skill implements a mechanism where local project configuration files, such as CLAUDE.md and .claude/rules/arise.md, are explicitly prioritized over global session rules. This design pattern creates a vulnerability surface for indirect prompt injection.
  • Ingestion points: The agent reads data from <root>/CLAUDE.md, .claude/wiki/index.md, and mempalace.yaml from folders located on the user's desktop.
  • Boundary markers: No boundary markers or 'ignore embedded instructions' warnings are present; the skill explicitly directs the agent to 'follow' and 'adopt' the rules found in these files.
  • Capability inventory: The agent retains file system access (read/write) and shell execution capabilities while 'awake' in the project.
  • Sanitization: There is no evidence of sanitization or validation of the content read from the project-specific files before it is incorporated into the agent's context.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 17, 2026, 01:13 PM