memory-management
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill contains explicit instructions to override and ignore base system directives. Specifically, it commands the agent to ignore 'repoMemoryInstructions' and 'OVERRIDE' native platform features, which is a pattern used to control or modify the underlying agent's default behavior.
- [INDIRECT_PROMPT_INJECTION]: The skill establishes a workflow where the agent continuously reads from and updates durable memory files (
project_decisions.md,error_patterns.md) within the repository. Because these files are stored in the codebase, they can be modified by any contributor or through external pull requests, creating a surface for malicious instructions to be ingested and followed by the agent in future sessions. - Ingestion points: Markdown files located in the
.agent-memory/directory. - Boundary markers: The skill relies on Markdown headers for structure but does not include explicit delimiters or instructions to ignore potential commands embedded within the data it reads.
- Capability inventory: The system is designed to perform file writes and delegate tasks based on the contents of its memory.
- Sanitization: No sanitization or verification logic is provided to filter out instructions from the ingested project facts.
Audit Metadata