context-memory-keeper
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill functions as a state aggregator that reads data from various JSON manifests and reports.
- Ingestion points: The file
scripts/update_workflow_memory.pyreads data from multiple sources includingpaper_output/input_manifest.json,paper_output/qa/workflow_guard_report.json, andpaper_output/results/run_manifest.json. - Boundary markers: The summary generated in
workflow_memory.mduses standard Markdown formatting but lacks explicit boundary markers or "ignore embedded instructions" warnings for the interpolated data. - Capability inventory: The skill performs local script execution via Python.
- Sanitization: The script performs basic string conversion and list limiting (e.g., slicing failures to 20 items) but does not sanitize content against prompt injection patterns. If a project manifest contains malicious instructions, they could be promoted into the agent's active context.
- [COMMAND_EXECUTION]: The skill's core workflow relies on the execution of Python scripts to maintain state and verify the environment. Evidence:
SKILL.mdcontains instructions for the agent to runpython .claude/skills/context-memory-keeper/scripts/update_workflow_memory.pyandpython .claude/skills/paper-workflow-orchestrator/scripts/workflow_guard.py.
Audit Metadata