agent-memory-workflow
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill mandates a recall ritual at the start of every session that loads historical data into the agent's current context.
- Ingestion points: Untrusted data enters the agent context through
memory_smart_search,memory_recall,memory_file_history, and the.opencode/memory/directory. - Boundary markers: The instructions lack explicit boundary markers or "ignore embedded instructions" warnings when synthesizing the recalled context into the session summary.
- Capability inventory: The skill uses
memory_saveto write to persistent storage and the Write tool to create local JSON files in the fallback scenario. - Sanitization: No sanitization or validation is performed on retrieved memory content before it is processed by the agent.
Audit Metadata