evo-memory

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill maintains a persistent learning layer that ingests data from external sources and stores it across sessions, creating a risk of cross-session indirect prompt injection.\n
  • Ingestion points: The skill reads from tournament summaries (/direction-summary.md in ide-protocol.md), experiment trajectory logs (/experiments/stage*_method/trajectory.md in ese-protocol.md), and research proposals.\n
  • Boundary markers: The memory templates in assets/ideation-memory-template.md and assets/experiment-memory-template.md do not utilize specific delimiters (e.g., XML tags or unique markers) or "ignore instructions" warnings to isolate external content from the agent's core instructions.\n
  • Capability inventory: The skill uses write_file, edit_file, and read_file to maintain its memory stores. While this skill does not execute code directly, the context it provides to future cycles (like experiment-pipeline) can influence skills that possess significant code execution capabilities.\n
  • Sanitization: The extraction protocols (IDE, IVE, ESE) rely on LLM-based summarization but do not specify explicit sanitization, escaping, or filtering of potentially malicious instructions embedded in the source data.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 08:21 AM