evo-memory
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill maintains a persistent learning layer that ingests data from external sources and stores it across sessions, creating a risk of cross-session indirect prompt injection.\n
- Ingestion points: The skill reads from tournament summaries (
/direction-summary.mdinide-protocol.md), experiment trajectory logs (/experiments/stage*_method/trajectory.mdinese-protocol.md), and research proposals.\n - Boundary markers: The memory templates in
assets/ideation-memory-template.mdandassets/experiment-memory-template.mddo not utilize specific delimiters (e.g., XML tags or unique markers) or "ignore instructions" warnings to isolate external content from the agent's core instructions.\n - Capability inventory: The skill uses
write_file,edit_file, andread_fileto maintain its memory stores. While this skill does not execute code directly, the context it provides to future cycles (likeexperiment-pipeline) can influence skills that possess significant code execution capabilities.\n - Sanitization: The extraction protocols (
IDE,IVE,ESE) rely on LLM-based summarization but do not specify explicit sanitization, escaping, or filtering of potentially malicious instructions embedded in the source data.
Audit Metadata