instinct-system

Pass

Audited by Gen Agent Trust Hub on Jul 22, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructions (LITE.md) direct the agent to execute local shell commands. Specifically, it uses sqlite3 to query a cognitive graph database (.forgewright/memory.db) and python3 to run a maintenance script (scripts/mem0-v2.py) for adjusting memory weights.
  • [PROMPT_INJECTION]: The system is designed to monitor and analyze tool call sequences and arguments to identify workflow patterns, which presents an indirect prompt injection surface (Category 8).
  • Ingestion points: The observer hook in SKILL.md captures metadata and arguments from every tool call executed by the agent.
  • Boundary markers: There are no documented boundary markers or instructions used to sanitize or isolate the ingested tool data during the pattern analysis phase.
  • Capability inventory: The skill can execute shell commands and modify local storage, providing a path for actions based on learned patterns.
  • Sanitization: While the system uses a hashArguments setting to protect the privacy of tool inputs, this does not prevent the pattern-recognition engine from being influenced by intentionally crafted tool call sequences.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 22, 2026, 08:30 AM
Security Audit — agent-trust-hub — instinct-system