memory
Warn
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTIONCREDENTIALS_UNSAFEDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill frequently uses
subprocess.runto call system utilities such asffprobefor media metadata extraction (horus_lore_chunking.py) and to proxy commands to an external project located atMEMORY_ROOTviauv run(run.sh). It also interacts with other agent skills includingcreate-persona,scheduler,dogpile, andscillmto perform specialized tasks. - [COMMAND_EXECUTION]: A persistence mechanism is implemented in
persona_journal.py, which calls aschedulerskill to register a nightly cron job (0 3 * * *). This ensures that persona journal entries are generated automatically every day, allowing the agent to maintain a persistent 'psychological' state across sessions. - [PROMPT_INJECTION]: The skill uses detailed persona definitions (e.g.,
HORUS_PERSONA.md) that specify complex behavioral traits and behavioral constraints. It also ingests untrusted data from YouTube transcripts and audiobooks (horus_lore_ingest.py), which is summarized and then injected into the agent's system prompt as 'subconscious' context (horus_lore_query.py), representing a significant vector for indirect prompt injection. - [CREDENTIALS_UNSAFE]: The database connection utility
db.pyrelies on environment variables (ARANGO_USER,ARANGO_PASS) to handle ArangoDB authentication. This practice, while common, can lead to sensitive credential exposure if the environment configuration is leaked or improperly secured. - [DATA_EXFILTRATION]: Comprehensive logging of user interactions and agent responses is performed by
brandon_audit.py, which stores session data in local JSONL files within thelogs/directory. While this data is not transmitted over the network, the accumulation of sensitive interaction history locally presents a data exposure risk.
Audit Metadata