memory-manager
Pass
Audited by Gen Agent Trust Hub on May 1, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill facilitates persistent memory by ingesting project-related data that is later retrieved and used to populate the agent's prompt context during session starts.\n
- Ingestion points: Untrusted data can enter the system through the
addcommand, themigratefunction for legacy logs, and automated hooks likeTURN_CLOSEorERRORwhich summarize session activity into the database.\n - Boundary markers: The skill documentation does not describe the use of XML tags or specific 'ignore instructions' delimiters when the retrieved memory content is presented back to the LLM.\n
- Capability inventory: The skill possesses the ability to read and write to the local file system via SQLite (
memory.db) and execute local Python scripts defined in thescripts/directory.\n - Sanitization: The system features proactive redaction of secrets (e.g., API keys, passwords) based on regex patterns, but it lacks specific sanitization or filtering to prevent natural language instructions embedded in memories from being executed by the agent.\n- [COMMAND_EXECUTION]: The skill instructs the agent to execute local Python scripts (
scripts/mem0-v2.py) for setup, data entry, and maintenance tasks. This is a standard functional requirement for the skill but constitutes an execution surface for local code.
Audit Metadata