memory-manager

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and act upon data stored in external files, specifically memory/MEMORY_ENTRY.md. This creates a potential surface for indirect prompt injection if the memory files are populated with untrusted content.
  • Ingestion points: The agent is instructed to retrieve information from memory/MEMORY_ENTRY.md and various defined memory layers like AUTHOR_PROFILE and NOVEL_CANON.
  • Boundary markers: The skill contains instructions to prioritize current authoritative files over retrieved memory and to verify recalled facts, which provides a logical boundary but not a technical sandbox.
  • Capability inventory: The instructions imply the agent will use file read and write tools to maintain and retrieve the memory state.
  • Sanitization: The instructions do not specify any sanitization or filtering of the retrieved memory content to prevent embedded instructions from being executed.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 02:39 PM