context-memory-keeper

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill functions as a state aggregator that reads data from various JSON manifests and reports.
  • Ingestion points: The file scripts/update_workflow_memory.py reads data from multiple sources including paper_output/input_manifest.json, paper_output/qa/workflow_guard_report.json, and paper_output/results/run_manifest.json.
  • Boundary markers: The summary generated in workflow_memory.md uses standard Markdown formatting but lacks explicit boundary markers or "ignore embedded instructions" warnings for the interpolated data.
  • Capability inventory: The skill performs local script execution via Python.
  • Sanitization: The script performs basic string conversion and list limiting (e.g., slicing failures to 20 items) but does not sanitize content against prompt injection patterns. If a project manifest contains malicious instructions, they could be promoted into the agent's active context.
  • [COMMAND_EXECUTION]: The skill's core workflow relies on the execution of Python scripts to maintain state and verify the environment. Evidence: SKILL.md contains instructions for the agent to run python .claude/skills/context-memory-keeper/scripts/update_workflow_memory.py and python .claude/skills/paper-workflow-orchestrator/scripts/workflow_guard.py.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 02:58 PM