Audit History
agent-memory - 8 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v8 Latest | Jul 21, 2026, 08:30 AM | No confirmed findings | 0 | No capability change |
| v7 | Jul 8, 2026, 10:37 AM | 1 confirmed | 0 | No capability change |
| v6 | Jul 1, 2026, 01:15 AM | No confirmed findings | 2 | No capability change |
| v5 | Jul 1, 2026, 01:15 AM | No confirmed findings | 2 | No capability change |
| v4 | Jan 17, 2026, 08:52 AM | No confirmed findings | 0 | No capability change |
| v3 | Jan 17, 2026, 08:52 AM | No confirmed findings | 0 | Filesystem accessExternal commands |
| v2 | Jan 4, 2026, 04:45 PM | No confirmed findings | 0 | No capability change |
| v1 | Jan 4, 2026, 04:45 PM | No confirmed findings | 0 | Baseline |
Jul 21, 2026, 08:30 AM
All 19 static findings are false positives. The reported shell-execution findings identify Markdown code fences and inline code, not executed commands. The documented commands operate only on the skill's local memory directory, and no prompt injection, credential access, network activity, or data-exfiltration intent was found.
Risk Factors
⚙️ External commands (16)
📁 Filesystem access (1)
Jul 8, 2026, 10:37 AM
Most static findings are Markdown backticks, fenced examples, or fixed-path shell snippets used to document local memory operations. No prompt injection, network access, credential access, or malicious command construction was found, but persistent proactive memory storage creates a privacy risk if sensitive information is saved.
Confirmed security concerns (1)
Risk Factors
⚙️ External commands (16)
📁 Filesystem access (1)
Jul 1, 2026, 01:15 AM
Static analysis flagged Markdown backticks, weak-crypto terms, and system-reconnaissance patterns, but review found no cryptography, network access, or prompt injection. The confirmed risk is limited to documented local shell commands that search, create, write, and remove memory files. The skill is safe to publish with a low-risk warning for local filesystem changes.
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (3)
📁 Filesystem access (2)
Detected Patterns
Jul 1, 2026, 01:15 AM
Static analysis flagged Markdown backticks, weak-crypto terms, and system-reconnaissance patterns, but review found no cryptography, network access, or prompt injection. The confirmed risk is limited to documented local shell commands that search, create, write, and remove memory files. The skill is safe to publish with a low-risk warning for local filesystem changes.
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (3)
📁 Filesystem access (2)
Detected Patterns
Jan 17, 2026, 08:52 AM
This is a pure documentation skill with no code execution capabilities. It defines memory storage structure and usage guidelines. All 37 static findings are false positives: the scanner incorrectly flagged markdown formatting and YAML field names as security issues. No scripts, network calls, or external commands exist.
Risk Factors
📁 Filesystem access (1)
Jan 17, 2026, 08:52 AM
This is a pure documentation skill with no code execution capabilities. It defines memory storage structure and usage guidelines. All 37 static findings are false positives: the scanner incorrectly flagged markdown formatting and YAML field names as security issues. No scripts, network calls, or external commands exist.
Risk Factors
📁 Filesystem access (1)
Jan 4, 2026, 04:45 PM
This is a pure prompt-based documentation skill with no code execution capabilities. It defines memory storage structure and usage guidelines for Claude agents. Contains no scripts, network calls, filesystem access beyond standard skill directory, environment variable access, or external command execution.
Jan 4, 2026, 04:45 PM
This is a pure prompt-based documentation skill with no code execution capabilities. It defines memory storage structure and usage guidelines for Claude agents. Contains no scripts, network calls, filesystem access beyond standard skill directory, environment variable access, or external command execution.