bezalel-memory

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external, potentially untrusted data, creating an attack surface for indirect prompt injection.
  • Ingestion points: Data enters the agent context through the memory__search tool, which retrieves facts and document excerpts, and the memory__ingest_session tool, which processes full session transcripts (SKILL.md).
  • Boundary markers: The instructions do not specify the use of delimiters or boundary markers to differentiate between system instructions and data retrieved from memory.
  • Capability inventory: The skill includes capabilities to search, add, ingest, and forget data in a long-term storage system (SKILL.md).
  • Sanitization: There is a mention of stripping secrets before ingestion, but no specific guidance on sanitizing or filtering instructions that might be embedded in the retrieved memory chunks or transcripts.
  • [EXTERNAL_DOWNLOADS]: The skill documentation references the @goshen/bezalel extension and the bezalel connect CLI tool as components of the memory architecture (SKILL.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:56 PM
Security Audit — agent-trust-hub — bezalel-memory