tree-ring-memory
Pass
Audited by Gen Agent Trust Hub on Aug 8, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to interact with the local environment using the 'tree-ring' CLI tool. Commands include help, recall, synchronization, and scanning of source roots to manage project memory.\n- [PROMPT_INJECTION]: The skill processes content from untrusted external sources, such as repository documents and project-local configuration files, creating a surface for indirect prompt injection.\n
- Ingestion points: The agent reads '.tree-ring/SKILL.md', 'AGENTS.md', and various project source documents during the sync and recall workflows.\n
- Boundary markers: While the instructions do not specify technical delimiters, they explicitly command the agent to verify evidence and only store concise, useful summaries.\n
- Capability inventory: The agent uses shell command execution to interface with the 'tree-ring' tool.\n
- Sanitization: The 'Privacy Guardrails' section provides clear instructions to redact secrets, tokens, and sensitive personal information, and to avoid treating unverified claims as project truth.
Audit Metadata