importing-chatgpt-memory

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data in the form of ChatGPT export zip files, which could contain malicious instructions embedded within message content or conversation metadata.
  • Ingestion points: Multiple scripts (list-conversations.py, extract-saved-memory.py, render-conversation.py) read and parse data from user-provided ZIP archives.
  • Boundary markers: While the skill provides high-level extraction guidance (e.g., focusing on about_user_message), it does not implement strict boundary delimiters or 'ignore' instructions for the content being processed.
  • Capability inventory: The agent has the capability to modify durable memory files (system/human.md) and execute local shell commands based on its analysis of this data.
  • Sanitization: The extraction scripts perform basic text normalization, but the semantic interpretation and subsequent memory updates are performed by the LLM, creating a potential injection surface.
  • [DYNAMIC_EXECUTION]: The skill uses dynamic Python loading mechanisms and subprocess calls to coordinate tasks between its internal scripts.
  • scripts/build-memory-preview.py and scripts/render-range.py utilize importlib.util to dynamically load and execute other scripts within the local scripts/ directory at runtime.
  • scripts/export-transcripts.py uses subprocess.run() to execute render-conversation.py as a separate process.
  • These techniques are used for legitimate modular orchestration but represent a dynamic execution pattern.
  • [COMMAND_EXECUTION]: The workflow involves the execution of various shell commands to manage the migration process.
  • Memory Versioning: The skill uses git commands (git log, git reset --hard, git push --force) to create rollback points for the memory directory before making changes.
  • File Discovery: The instructions use shell utilities like ls, grep, and unzip to locate ChatGPT exports in the user's ~/Downloads directory and verify their contents.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:46 PM
Security Audit — agent-trust-hub — importing-chatgpt-memory