dreaming-consolidator

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructions provide bash commands for creating and removing marker files in ~/.claude/cooking/ using ps, mkdir, printf, and rm to track active execution.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its core function of reading and synthesizing data from the auto-memory graph.
  • Ingestion points: Reads every .md file located under ~/.claude/projects/*/memory/ as described in SKILL.md.
  • Boundary markers: The skill lacks explicit instructions or markers to distinguish between data and potential instructions within the memory files.
  • Capability inventory: Performs broad file reads and writes a synthesized output to a file outside the memory directory.
  • Sanitization: No content sanitization or instruction-filtering is specified for the ingested markdown data.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 11:52 AM
Security Audit — agent-trust-hub — dreaming-consolidator