code-memory-router
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The
inspect_embedding_metadata.pyscript scans project files and extracts text snippets that are fed back into the agent's context. This allows untrusted content from the codebase to potentially influence agent behavior. \n - Ingestion points: The script scans various files in the repository root, including
CLAUDE.md,MEMORY.md, and configuration files like.mcp.json. \n - Boundary markers: No delimiters or ignore instructions are provided in the script output to prevent the agent from following instructions embedded in the scanned files. \n
- Capability inventory: The skill can execute shell commands and perform file system operations via the
qmdandmempalaceCLI tools. \n - Sanitization: Extracted snippets are not filtered or sanitized before being presented to the agent. \n- [DYNAMIC_EXECUTION]: The skill executes a bundled Python script (
scripts/inspect_embedding_metadata.py) to analyze the workspace environment and detect tool configurations at runtime. \n- [COMMAND_EXECUTION]: The skill instructs the agent to execute external CLI tools (qmdandmempalace) via shell commands to perform codebase and memory searches.
Audit Metadata