memory-sanitize — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited memory-sanitize (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Redact PII and scan for credentials in memory files — write copies to /tmp, never touch originals.
Memory-dir-only. Does not read session histories. Structural audit (orphans, duplicates) belongs in memory-clean; run that first if the directory is messy. This skill is a best-effort redactor, not a formal DLP tool — the user is the final reviewer.
SKILL_SCRIPTS="${MEMORY_SANITIZE_SKILL_SCRIPTS:-$HOME/.claude/claude/skills/memory-sanitize/scripts}"
MEMORY_DIR=$("$SKILL_SCRIPTS/resolve-paths.sh" memory_dir)SESSION_HISTORY_GLOB is not used by this skill. Abort on non-zero exit. Override MEMORY_SANITIZE_SKILL_SCRIPTS if installed outside $HOME/.claude.
DST="/tmp/memory-sanitized-$(date +%s)"
"$SKILL_SCRIPTS/sanitize-memory.sh" "$MEMORY_DIR" "$DST"The script writes redacted copies under $DST/ and emits a JSON report to stdout:
{
"files": [
{ "source": "feedback_foo.md", "redactions": 3, "credentials": 0 },
{ "source": "MEMORY.md", "redactions": 1, "credentials": 1 }
],
"total_redactions": 4,
"total_credentials": 1
}Read references/REDACTION-RULES.md for the full pattern table and severity tiers.
difft "$MEMORY_DIR" "$DST"For each file with credential hits, show the specific line(s) with the hit pattern highlighted. If any credential remains in the source originals (zero redaction applied despite a credential pattern match), abort with a critical warning and recommend the user manually remediate the original before sharing.
Render:
Sanitized N files → $DST
N redactions applied (paths, emails, session IDs, dates)
N credential hits (see above)
Original files are unchanged. Review the diff before sharing.Wait for user acknowledgement before exiting.
/tmp/memory-sanitized-<ts>/.MEMORY.md in the originals — sanitized copies are not a replacement.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.