persistent-memory

Warn

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: Uses bash commands to create directories, manage files, and generate shell scripts (~/.claude/remember.sh) in the home directory.
  • [COMMAND_EXECUTION]: Instructs the agent to modify configuration files (~/.claude/settings.json) to establish hooks that execute shell commands automatically at session start.
  • [PROMPT_INJECTION]: Explicitly directs the agent to load unvetted content into the system prompt, enabling persistent behavior modification across sessions.
  • [PROMPT_INJECTION]: Uses high-pressure language to override default session boundaries.
  • [DATA_EXFILTRATION]: Accesses and modifies files in sensitive paths within the home directory (~/.claude/).
  • [PROMPT_INJECTION]: (Indirect Prompt Injection surface) 1. Ingestion points: User input and session context (SKILL.md). 2. Boundary markers: Absent. 3. Capability inventory: Bash and file-writing tools. 4. Sanitization: Absent; content is re-injected verbatim.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 22, 2026, 10:50 AM
Security Audit — agent-trust-hub — persistent-memory