supermemory-search
Pass
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a local Node.js utility
~/.codex/supermemory/search-memory.jsto query past coding data. This is a vendor-provided tool for memory retrieval. - [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface. Ingestion points: Results from search-memory.js in SKILL.md. Boundary markers: No delimiters are used to wrap search results. Capability inventory: Node.js execution through Bash. Sanitization: Content from memories is not explicitly sanitized before being processed by the agent. This surface is consistent with the skill's intended functionality.
Audit Metadata