agent-memory-workflow

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill mandates a recall ritual at the start of every session that loads historical data into the agent's current context.
  • Ingestion points: Untrusted data enters the agent context through memory_smart_search, memory_recall, memory_file_history, and the .opencode/memory/ directory.
  • Boundary markers: The instructions lack explicit boundary markers or "ignore embedded instructions" warnings when synthesizing the recalled context into the session summary.
  • Capability inventory: The skill uses memory_save to write to persistent storage and the Write tool to create local JSON files in the fallback scenario.
  • Sanitization: No sanitization or validation is performed on retrieved memory content before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 02:38 AM
Security Audit — agent-trust-hub — agent-memory-workflow