agents-memory

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists of administrative and auditing utilities for managing agent memory files. No malicious patterns or attack vectors were detected during the analysis.
  • [CREDENTIALS_UNSAFE]: The scripts/lint_claude_memory.sh script contains a regular expression designed to scan for and detect hardcoded secrets within the repository's memory files (e.g., OPENAI_API_KEY, AWS_SECRET_ACCESS_KEY, GITHUB_TOKEN). This is implemented as a defensive security auditing feature to prevent accidental credential exposure.
  • [COMMAND_EXECUTION]: The provided scripts (audit_repo.sh, audit_portfolio.sh, lint_claude_memory.sh, compare_blocks.sh) utilize standard Unix utilities like find, grep, awk, md5sum, and sed to perform static analysis of markdown files. These scripts operate locally on the repository files and do not perform unauthorized or dangerous command execution.
  • [EXTERNAL_DOWNLOADS]: The documentation references established development tools and package registries (e.g., npm, pnpm, uv, agent-browser). These references are provided for legitimate environment configuration and do not involve suspicious piping of remote content to shell interpreters.
  • [INDIRECT_PROMPT_INJECTION]: The skill manages the instruction files that govern agent behavior. It addresses the risks associated with this attack surface by providing validators to catch 'Hallucination-Bait Patterns' and stale instructions that could lead to unintended agent actions. The skill functions as a management layer to ensure instructions remain concise, accurate, and safe.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:07 PM
Security Audit — agent-trust-hub — agents-memory