tree-ring-memory

Pass

Audited by Gen Agent Trust Hub on Aug 8, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to interact with the local environment using the 'tree-ring' CLI tool. Commands include help, recall, synchronization, and scanning of source roots to manage project memory.\n- [PROMPT_INJECTION]: The skill processes content from untrusted external sources, such as repository documents and project-local configuration files, creating a surface for indirect prompt injection.\n
  • Ingestion points: The agent reads '.tree-ring/SKILL.md', 'AGENTS.md', and various project source documents during the sync and recall workflows.\n
  • Boundary markers: While the instructions do not specify technical delimiters, they explicitly command the agent to verify evidence and only store concise, useful summaries.\n
  • Capability inventory: The agent uses shell command execution to interface with the 'tree-ring' tool.\n
  • Sanitization: The 'Privacy Guardrails' section provides clear instructions to redact secrets, tokens, and sensitive personal information, and to avoid treating unverified claims as project truth.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 8, 2026, 03:36 PM
Security Audit — agent-trust-hub — tree-ring-memory