auto-memory

Pass

Audited by Gen Agent Trust Hub on Apr 5, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill creates an indirect prompt injection surface by extracting information from user conversations and persisting it to a 'steering' file (.kiro/steering/memory.md) that is automatically loaded in subsequent sessions to influence agent behavior.
  • Ingestion points: Live conversation history and user-provided feedback (Phase 1).
  • Boundary markers: None specified for the output file format; entries are appended as raw text lines.
  • Capability inventory: File system read and write access to the project's configuration directory (Phase 2 and 3).
  • Sanitization: No explicit validation or filtering of extracted content is performed before persistence.
  • [COMMAND_EXECUTION]: The skill performs local file system operations to manage persistent project state, including reading, writing, and archiving files within the .kiro/ directory structure.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 5, 2026, 12:44 AM
Security Audit — agent-trust-hub — auto-memory