memory-management

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains explicit instructions to override and ignore base system directives. Specifically, it commands the agent to ignore 'repoMemoryInstructions' and 'OVERRIDE' native platform features, which is a pattern used to control or modify the underlying agent's default behavior.
  • [INDIRECT_PROMPT_INJECTION]: The skill establishes a workflow where the agent continuously reads from and updates durable memory files (project_decisions.md, error_patterns.md) within the repository. Because these files are stored in the codebase, they can be modified by any contributor or through external pull requests, creating a surface for malicious instructions to be ingested and followed by the agent in future sessions.
  • Ingestion points: Markdown files located in the .agent-memory/ directory.
  • Boundary markers: The skill relies on Markdown headers for structure but does not include explicit delimiters or instructions to ignore potential commands embedded within the data it reads.
  • Capability inventory: The system is designed to perform file writes and delegate tasks based on the contents of its memory.
  • Sanitization: No sanitization or verification logic is provided to filter out instructions from the ingested project facts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 10:30 AM
Security Audit — agent-trust-hub — memory-management