agentmemory

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the @agentmemory/agentmemory Node.js package, which is executed via npx to run the memory server on localhost. This package is the primary dependency for the skill's stated purpose of session memory.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes historical data and observations from past sessions, which presents a surface for indirect prompt injection. If malicious instructions are stored in memory, they could influence the agent's behavior upon recall.\n
  • Ingestion points: Found in the memory_recall, memory_smart_search, memory_sessions, memory_file_history, and memory_lesson_recall tools defined in SKILL.md.\n
  • Boundary markers: No explicit boundary markers or delimiters are defined in the instructions to separate recalled memory content from the system prompt or active instructions.\n
  • Capability inventory: The skill has the capability to read from and write to a local persistent memory store, which is used to inform the agent's future actions and code edits.\n
  • Sanitization: No sanitization, validation, or filtering mechanisms for the recalled memory content are described in the skill documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 02:38 AM
Security Audit — agent-trust-hub — agentmemory