ForgetSAFE
A single hub to find Claude Skills, Agents, Commands, Hooks, Plugins, and Marketplace collections to extend Claude Code, Claude Desktop, Agent SDK and OpenClaw
Overview
A single hub to find Claude Skills, Agents, Commands, Hooks, Plugins, and Marketplace collections to extend Claude Code, Claude Desktop, Agent SDK and OpenClaw
80a0afd96301OBSERVED · 2026-10-07What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
---
name: forget
description: >
Delete a memory from Origin by ID. Destructive and cannot be undone —
prefer `/capture` with `supersedes` for corrections. Invoked as
`/forget <source_id>`.
argument-hint: "<source_id>"
allowed-tools: ["Bash", "mcp__plugin_origin_origin__forget", "mcp__plugin_origin_origin__recall"]
---
# /forget
Permanently delete a memory by its `source_id`.
## How to invoke
You need the `source_id`. If the user did not provide it, call
`/recall` first to find the matching memory and confirm with the
user before deleting.
```
forget(memory_id="<source_id>")
```
## When to use
- User says "forget this", "delete that", "that's wrong, remove it".
- User explicitly identifies a memory by ID.
## When NOT to use
- For corrections, prefer storing a new memory with `supersedes` pointing
at the old one. That preserves history. Use `/capture` with the
`supersedes` arg instead.
- Bulk deletions — call `/review` first, confirm with the user,
then delete one at a time.
## Safety
Deletion is destructive. Always confirm with the user before calling forget,
unless the user has already given an explicit, unambiguous instruction in
the same turn (e.g. they pasted the ID and said "delete this").
## Auto-commit ~/.origin/
If the deletion removed a page md (daemon archives the page and
KnowledgeWriter unlinks the file), snapshot the change. Defensive —
silent skip if `git` missing, `~/.origin/` not a repo, or no diff.
```
Bash: git -C ~/.origin add -A && \
git -C ~/.origin -c user.name=Origin -c [email protected] \
commit --quiet -m "forget: <source_id>" 2>/dev/null || \
(sleep 1 && git -C ~/.origin add -A && \
git -C ~/.origin -c user.name=Origin -c [email protected] \
commit --quiet -m "forget: <source_id>" 2>/dev/null) || true
```
The retry handles index.lock races — the daemon may be writing to
`~/.origin/` at the same moment (auto-commit from captures). One-second
wait is enough for the daemon to release the lock.Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
80a0afd96301full audit observations/trust-audit/skill/davepoon__forget.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 80a0afd96301 | SAFE | B | 89 | first audit |
Questions
What does the Forget skill do?
A single hub to find Claude Skills, Agents, Commands, Hooks, Plugins, and Marketplace collections to extend Claude Code, Claude Desktop, Agent SDK and OpenClaw
Is Forget safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Forget access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
What do I need installed to use Forget?
Its own instructions reference source_id. Dependencies are pinned to exact versions.
How current is this page?
The grade is for one exact copy of the source (80a0afd96301), read on 2026-10-07. The repository is watched, and a new audit runs when it changes — this is the first audit.