supermemory-search

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a local Node.js utility ~/.codex/supermemory/search-memory.js to query past coding data. This is a vendor-provided tool for memory retrieval.
  • [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface. Ingestion points: Results from search-memory.js in SKILL.md. Boundary markers: No delimiters are used to wrap search results. Capability inventory: Node.js execution through Bash. Sanitization: Content from memories is not explicitly sanitized before being processed by the agent. This surface is consistent with the skill's intended functionality.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 03:27 AM
Security Audit — agent-trust-hub — supermemory-search