letta-filesystem-to-memfs

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/letta_fs_to_memfs.py executes the qmd CLI utility using subprocess.run to manage semantic search indices and queries.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests content from untrusted external URLs and local documents, processing them into memory chunks accessible by the agent.
  • Ingestion points: File paths and URLs provided via the --source argument in the ingest command of scripts/letta_fs_to_memfs.py.
  • Boundary markers: Chunks are stored in markdown files prefixed with YAML frontmatter metadata.
  • Capability inventory: The skill writes to the filesystem and executes external search and indexing commands.
  • Sanitization: Input filenames are normalized using a slugification function, and frontmatter values are escaped via JSON encoding.
  • [EXTERNAL_DOWNLOADS]: The download_source function in scripts/letta_fs_to_memfs.py uses urllib.request to fetch content from remote URLs. The documentation includes examples targeting well-known academic repositories like arXiv.
  • [REMOTE_CODE_EXECUTION]: The skill suggests the installation of a third-party Node.js package (@tobilu/qmd) from an unverified source to enable semantic search functionality. It also uses subprocess.run to execute this tool, representing a dependency on external code that runs with the agent's privileges.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:46 PM
Security Audit — agent-trust-hub — letta-filesystem-to-memfs