memory-manager

Pass

Audited by Gen Agent Trust Hub on May 1, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill facilitates persistent memory by ingesting project-related data that is later retrieved and used to populate the agent's prompt context during session starts.\n
  • Ingestion points: Untrusted data can enter the system through the add command, the migrate function for legacy logs, and automated hooks like TURN_CLOSE or ERROR which summarize session activity into the database.\n
  • Boundary markers: The skill documentation does not describe the use of XML tags or specific 'ignore instructions' delimiters when the retrieved memory content is presented back to the LLM.\n
  • Capability inventory: The skill possesses the ability to read and write to the local file system via SQLite (memory.db) and execute local Python scripts defined in the scripts/ directory.\n
  • Sanitization: The system features proactive redaction of secrets (e.g., API keys, passwords) based on regex patterns, but it lacks specific sanitization or filtering to prevent natural language instructions embedded in memories from being executed by the agent.\n- [COMMAND_EXECUTION]: The skill instructs the agent to execute local Python scripts (scripts/mem0-v2.py) for setup, data entry, and maintenance tasks. This is a standard functional requirement for the skill but constitutes an execution surface for local code.
Audit Metadata
Risk Level
SAFE
Analyzed
May 1, 2026, 08:02 AM
Security Audit — agent-trust-hub — memory-manager