code-memory-router

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The inspect_embedding_metadata.py script scans project files and extracts text snippets that are fed back into the agent's context. This allows untrusted content from the codebase to potentially influence agent behavior. \n
  • Ingestion points: The script scans various files in the repository root, including CLAUDE.md, MEMORY.md, and configuration files like .mcp.json. \n
  • Boundary markers: No delimiters or ignore instructions are provided in the script output to prevent the agent from following instructions embedded in the scanned files. \n
  • Capability inventory: The skill can execute shell commands and perform file system operations via the qmd and mempalace CLI tools. \n
  • Sanitization: Extracted snippets are not filtered or sanitized before being presented to the agent. \n- [DYNAMIC_EXECUTION]: The skill executes a bundled Python script (scripts/inspect_embedding_metadata.py) to analyze the workspace environment and detect tool configurations at runtime. \n- [COMMAND_EXECUTION]: The skill instructs the agent to execute external CLI tools (qmd and mempalace) via shell commands to perform codebase and memory searches.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 07:57 AM
Security Audit — agent-trust-hub — code-memory-router