preference-learner

Pass

Audited by Gen Agent Trust Hub on Apr 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill uses platform-native memory_read and memory_write permissions to store and retrieve user settings. There are no network operations, hardcoded credentials, or shell command executions.
  • [PROMPT_INJECTION]: The skill implements a preference learning mechanism that creates a surface for persistent indirect prompt injection (Category 8) by storing untrusted user strings to guide future behavior. This is handled as safe within the context of the skill's primary purpose.
  • Ingestion points: User input from triggers like 'I prefer', 'I like', and 'remember that I' defined in SKILL.md.
  • Boundary markers: None identified.
  • Capability inventory: memory_read and memory_write for persistence.
  • Sanitization: No sanitization of preference strings is specified.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 18, 2026, 12:42 AM
Security Audit — agent-trust-hub — preference-learner