memory-manager
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and act upon data stored in external files, specifically
memory/MEMORY_ENTRY.md. This creates a potential surface for indirect prompt injection if the memory files are populated with untrusted content. - Ingestion points: The agent is instructed to retrieve information from
memory/MEMORY_ENTRY.mdand various defined memory layers like AUTHOR_PROFILE and NOVEL_CANON. - Boundary markers: The skill contains instructions to prioritize current authoritative files over retrieved memory and to verify recalled facts, which provides a logical boundary but not a technical sandbox.
- Capability inventory: The instructions imply the agent will use file read and write tools to maintain and retrieve the memory state.
- Sanitization: The instructions do not specify any sanitization or filtering of the retrieved memory content to prevent embedded instructions from being executed.
Audit Metadata