importing-chatgpt-memory
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data in the form of ChatGPT export zip files, which could contain malicious instructions embedded within message content or conversation metadata.
- Ingestion points: Multiple scripts (
list-conversations.py,extract-saved-memory.py,render-conversation.py) read and parse data from user-provided ZIP archives. - Boundary markers: While the skill provides high-level extraction guidance (e.g., focusing on
about_user_message), it does not implement strict boundary delimiters or 'ignore' instructions for the content being processed. - Capability inventory: The agent has the capability to modify durable memory files (
system/human.md) and execute local shell commands based on its analysis of this data. - Sanitization: The extraction scripts perform basic text normalization, but the semantic interpretation and subsequent memory updates are performed by the LLM, creating a potential injection surface.
- [DYNAMIC_EXECUTION]: The skill uses dynamic Python loading mechanisms and subprocess calls to coordinate tasks between its internal scripts.
scripts/build-memory-preview.pyandscripts/render-range.pyutilizeimportlib.utilto dynamically load and execute other scripts within the localscripts/directory at runtime.scripts/export-transcripts.pyusessubprocess.run()to executerender-conversation.pyas a separate process.- These techniques are used for legitimate modular orchestration but represent a dynamic execution pattern.
- [COMMAND_EXECUTION]: The workflow involves the execution of various shell commands to manage the migration process.
- Memory Versioning: The skill uses
gitcommands (git log,git reset --hard,git push --force) to create rollback points for the memory directory before making changes. - File Discovery: The instructions use shell utilities like
ls,grep, andunzipto locate ChatGPT exports in the user's~/Downloadsdirectory and verify their contents.
Audit Metadata