letta-filesystem-to-memfs
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/letta_fs_to_memfs.pyexecutes theqmdCLI utility usingsubprocess.runto manage semantic search indices and queries. - [INDIRECT_PROMPT_INJECTION]: The skill ingests content from untrusted external URLs and local documents, processing them into memory chunks accessible by the agent.
- Ingestion points: File paths and URLs provided via the
--sourceargument in theingestcommand ofscripts/letta_fs_to_memfs.py. - Boundary markers: Chunks are stored in markdown files prefixed with YAML frontmatter metadata.
- Capability inventory: The skill writes to the filesystem and executes external search and indexing commands.
- Sanitization: Input filenames are normalized using a slugification function, and frontmatter values are escaped via JSON encoding.
- [EXTERNAL_DOWNLOADS]: The
download_sourcefunction inscripts/letta_fs_to_memfs.pyusesurllib.requestto fetch content from remote URLs. The documentation includes examples targeting well-known academic repositories like arXiv. - [REMOTE_CODE_EXECUTION]: The skill suggests the installation of a third-party Node.js package (
@tobilu/qmd) from an unverified source to enable semantic search functionality. It also usessubprocess.runto execute this tool, representing a dependency on external code that runs with the agent's privileges.
Audit Metadata