awake
Pass
Audited by Gen Agent Trust Hub on Jul 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes shell commands using project-specific tools, notably the
mempalaceCLI (e.g.,mempalace wake-up). These tools are identified as resources associated with the vendor (Oruga420). - [PROMPT_INJECTION]: The skill implements a mechanism where local project configuration files, such as
CLAUDE.mdand.claude/rules/arise.md, are explicitly prioritized over global session rules. This design pattern creates a vulnerability surface for indirect prompt injection. - Ingestion points: The agent reads data from
<root>/CLAUDE.md,.claude/wiki/index.md, andmempalace.yamlfrom folders located on the user's desktop. - Boundary markers: No boundary markers or 'ignore embedded instructions' warnings are present; the skill explicitly directs the agent to 'follow' and 'adopt' the rules found in these files.
- Capability inventory: The agent retains file system access (read/write) and shell execution capabilities while 'awake' in the project.
- Sanitization: There is no evidence of sanitization or validation of the content read from the project-specific files before it is incorporated into the agent's context.
Audit Metadata