memory

Warn

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTIONCREDENTIALS_UNSAFEDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill frequently uses subprocess.run to call system utilities such as ffprobe for media metadata extraction (horus_lore_chunking.py) and to proxy commands to an external project located at MEMORY_ROOT via uv run (run.sh). It also interacts with other agent skills including create-persona, scheduler, dogpile, and scillm to perform specialized tasks.
  • [COMMAND_EXECUTION]: A persistence mechanism is implemented in persona_journal.py, which calls a scheduler skill to register a nightly cron job (0 3 * * *). This ensures that persona journal entries are generated automatically every day, allowing the agent to maintain a persistent 'psychological' state across sessions.
  • [PROMPT_INJECTION]: The skill uses detailed persona definitions (e.g., HORUS_PERSONA.md) that specify complex behavioral traits and behavioral constraints. It also ingests untrusted data from YouTube transcripts and audiobooks (horus_lore_ingest.py), which is summarized and then injected into the agent's system prompt as 'subconscious' context (horus_lore_query.py), representing a significant vector for indirect prompt injection.
  • [CREDENTIALS_UNSAFE]: The database connection utility db.py relies on environment variables (ARANGO_USER, ARANGO_PASS) to handle ArangoDB authentication. This practice, while common, can lead to sensitive credential exposure if the environment configuration is leaked or improperly secured.
  • [DATA_EXFILTRATION]: Comprehensive logging of user interactions and agent responses is performed by brandon_audit.py, which stores session data in local JSONL files within the logs/ directory. While this data is not transmitted over the network, the accumulation of sensitive interaction history locally presents a data exposure risk.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 17, 2026, 06:37 AM
Security Audit — agent-trust-hub — memory