memory
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the installation of the
basic-memoryPython package from PyPI. This is a standard dependency for the skill's stated purpose.- [COMMAND_EXECUTION]: The skill operates by executing various subcommands of thebasic-memoryCLI tool (e.g.,write-note,read-note,search-notes,build-context). This is the intended behavior for interfacing with the memory system.- [DATA_EXFILTRATION]: Thebasic-memory synccommand implies network activity to synchronize the local memory database with a remote service. While this is expected for a 'sync' feature, users should be aware that their stored notes may be transmitted externally.- [INDIRECT_PROMPT_INJECTION]: The skill retrieves previously stored notes to build context for the agent. If a note contains malicious instructions (e.g., injected by a third party or a previous malicious input), the agent might follow those instructions when the note is loaded back into its active context. - Ingestion points: Notes are retrieved via
read-note,search-notes, andbuild-contextinSKILL.md. - Boundary markers: No explicit boundary markers or 'ignore' instructions are defined to separate note content from system instructions.
- Capability inventory: The agent can execute shell commands, read files, and write files as part of its normal operation.
- Sanitization: There is no evidence of sanitization or filtering of the note content before it is interpolated into the agent's prompt.
Audit Metadata