hindsight-architect
Expert memory architect. Understands your application, identifies where memory adds value, and produces an implementation plan with bank config, tag schema, and code.
Install this skill
or
91/100
Security score
The hindsight-architect skill was audited on Aug 19, 2026 and we found 5 security issues across 3 threat categories. Review the findings below before installing.
Categories Tested
Security Issues
low line 17
Command substitution pattern
SourceSKILL.md
| 15 | # Hindsight skill preamble - detect environment and existing config |
| 16 | _HS_VERSION="0.1.0" |
| 17 | _BRANCH=$(git branch --show-current 2>/dev/null || echo "unknown") |
| 18 | _PROJECT=$(basename "$(git rev-parse --show-toplevel 2>/dev/null)" 2>/dev/null || basename "$(pwd)") |
| 19 |
low line 18
Command substitution pattern
SourceSKILL.md
| 16 | _HS_VERSION="0.1.0" |
| 17 | _BRANCH=$(git branch --show-current 2>/dev/null || echo "unknown") |
| 18 | _PROJECT=$(basename "$(git rev-parse --show-toplevel 2>/dev/null)" 2>/dev/null || basename "$(pwd)") |
| 19 | |
| 20 | # Detect existing Hindsight configuration |
low line 46
Access to home directory dotfiles
SourceSKILL.md
| 44 | |
| 45 | # 2. Global CLI config (less specific than project) |
| 46 | if [ "$_DEPLOY_MODE" = "unknown" ] && [ -f ~/.hindsight/config ]; then |
| 47 | _HS_CONFIGURED="yes" |
| 48 | if grep -q "api.hindsight.vectorize.io" ~/.hindsight/config 2>/dev/null; then |
low line 48
Access to home directory dotfiles
SourceSKILL.md
| 46 | if [ "$_DEPLOY_MODE" = "unknown" ] && [ -f ~/.hindsight/config ]; then |
| 47 | _HS_CONFIGURED="yes" |
| 48 | if grep -q "api.hindsight.vectorize.io" ~/.hindsight/config 2>/dev/null; then |
| 49 | _DEPLOY_MODE="cloud" |
| 50 | else |
medium line 281
False safety assurance
SourceSKILL.md
| 279 | - Hindsight analyzes the memories to find relevant ones — you don't need to pre-classify them |
| 280 | |
| 281 | **Tags use AND matching.** Only memories with ALL specified tags are included. This is fine because tags are identity scopes that naturally co-occur. |
| 282 | |
| 283 | **Mental model retrieval:** Fetching a mental model is a fast, direct lookup — not an expensive operation. Use `get_mental_model(bank_id, mental_model_id)` to fetch by ID, or `list_mental_models(bank_id)` to list all models in a bank. The application stores or derives the mental model ID and fetches the content directly. This is a key-value lookup, not a search — use it freely before every response when you need the model's content. |
Scanned on Aug 19, 2026
View Security Dashboard