agents-memory
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists of administrative and auditing utilities for managing agent memory files. No malicious patterns or attack vectors were detected during the analysis.
- [CREDENTIALS_UNSAFE]: The
scripts/lint_claude_memory.shscript contains a regular expression designed to scan for and detect hardcoded secrets within the repository's memory files (e.g.,OPENAI_API_KEY,AWS_SECRET_ACCESS_KEY,GITHUB_TOKEN). This is implemented as a defensive security auditing feature to prevent accidental credential exposure. - [COMMAND_EXECUTION]: The provided scripts (
audit_repo.sh,audit_portfolio.sh,lint_claude_memory.sh,compare_blocks.sh) utilize standard Unix utilities likefind,grep,awk,md5sum, andsedto perform static analysis of markdown files. These scripts operate locally on the repository files and do not perform unauthorized or dangerous command execution. - [EXTERNAL_DOWNLOADS]: The documentation references established development tools and package registries (e.g.,
npm,pnpm,uv,agent-browser). These references are provided for legitimate environment configuration and do not involve suspicious piping of remote content to shell interpreters. - [INDIRECT_PROMPT_INJECTION]: The skill manages the instruction files that govern agent behavior. It addresses the risks associated with this attack surface by providing validators to catch 'Hallucination-Bait Patterns' and stale instructions that could lead to unintended agent actions. The skill functions as a management layer to ensure instructions remain concise, accurate, and safe.
Audit Metadata