save
Pass
Audited by Gen Agent Trust Hub on May 11, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill reads from and writes to a shared memory space, creating a potential surface for indirect prompt injection. Ingestion points: The skill calls list_memories and read_memory("project_overview") in SKILL.md. Boundary markers: There are no delimiters or markers to distinguish retrieved data from instructions. Capability inventory: The skill utilizes write_memory to save state and update project context. Sanitization: The skill does not perform any sanitization of the content handled during the memory update process.
Audit Metadata