bezalel-memory
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external, potentially untrusted data, creating an attack surface for indirect prompt injection.
- Ingestion points: Data enters the agent context through the
memory__searchtool, which retrieves facts and document excerpts, and thememory__ingest_sessiontool, which processes full session transcripts (SKILL.md). - Boundary markers: The instructions do not specify the use of delimiters or boundary markers to differentiate between system instructions and data retrieved from memory.
- Capability inventory: The skill includes capabilities to search, add, ingest, and forget data in a long-term storage system (SKILL.md).
- Sanitization: There is a mention of stripping secrets before ingestion, but no specific guidance on sanitizing or filtering instructions that might be embedded in the retrieved memory chunks or transcripts.
- [EXTERNAL_DOWNLOADS]: The skill documentation references the
@goshen/bezalelextension and thebezalel connectCLI tool as components of the memory architecture (SKILL.md).
Audit Metadata