persistent-memory
Warn
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: Uses bash commands to create directories, manage files, and generate shell scripts (~/.claude/remember.sh) in the home directory.
- [COMMAND_EXECUTION]: Instructs the agent to modify configuration files (~/.claude/settings.json) to establish hooks that execute shell commands automatically at session start.
- [PROMPT_INJECTION]: Explicitly directs the agent to load unvetted content into the system prompt, enabling persistent behavior modification across sessions.
- [PROMPT_INJECTION]: Uses high-pressure language to override default session boundaries.
- [DATA_EXFILTRATION]: Accesses and modifies files in sensitive paths within the home directory (~/.claude/).
- [PROMPT_INJECTION]: (Indirect Prompt Injection surface) 1. Ingestion points: User input and session context (SKILL.md). 2. Boundary markers: Absent. 3. Capability inventory: Bash and file-writing tools. 4. Sanitization: Absent; content is re-injected verbatim.
Audit Metadata