instinct-system
Pass
Audited by Gen Agent Trust Hub on Jul 22, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructions (LITE.md) direct the agent to execute local shell commands. Specifically, it uses
sqlite3to query a cognitive graph database (.forgewright/memory.db) andpython3to run a maintenance script (scripts/mem0-v2.py) for adjusting memory weights. - [PROMPT_INJECTION]: The system is designed to monitor and analyze tool call sequences and arguments to identify workflow patterns, which presents an indirect prompt injection surface (Category 8).
- Ingestion points: The observer hook in
SKILL.mdcaptures metadata and arguments from every tool call executed by the agent. - Boundary markers: There are no documented boundary markers or instructions used to sanitize or isolate the ingested tool data during the pattern analysis phase.
- Capability inventory: The skill can execute shell commands and modify local storage, providing a path for actions based on learned patterns.
- Sanitization: While the system uses a
hashArgumentssetting to protect the privacy of tool inputs, this does not prevent the pattern-recognition engine from being influenced by intentionally crafted tool call sequences.
Audit Metadata