memory-merger
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes content from memory files which could potentially contain instructions. However, the risk is mitigated by a human-in-the-loop confirmation step defined in Step 2, where the agent must propose the memories for merger and wait for explicit user approval before proceeding to the merge phase.
- Ingestion points: The skill reads external content from
{domain}-memory.instructions.md(Step 1). - Boundary markers: The skill requires user verification of the proposed content before any merge occurs (Step 2).
- Capability inventory: The skill possesses file read and file write capabilities within the scope of prompt and instruction directories.
- Sanitization: The skill relies on user review as the primary sanitization mechanism before updating files.
- [SAFE]: No malicious code, obfuscation, or unauthorized data exfiltration patterns were detected. The file operations are confined to standard directories used for agent instructions (e.g.,
.github/instructions/and VS Code user data).
Audit Metadata