skills/letta-ai/skills/memfs-search/Gen Agent Trust Hub

memfs-search

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads approximately 2GB of GGUF model files from Hugging Face to the ~/.cache/qmd/models/ directory during the setup phase. This is standard behavior for the qmd tool to enable local embeddings without external API calls.- [COMMAND_EXECUTION]: The skill executes the qmd CLI tool through a bash wrapper script (scripts/memfs-search.sh). This script includes logic to prioritize specific Node.js runtimes by modifying the PATH environment variable during execution.- [INDIRECT_PROMPT_INJECTION]: The skill creates a vector index of all Markdown files in the agent's memory directory, which may contain untrusted data. Malicious content retrieved during a search could influence the agent's behavior. 1. Ingestion points: All files in the $MEMORY_DIR directory (referenced in SKILL.md and scripts/memfs-search.sh). 2. Boundary markers: The search output lacks explicit delimiters or instructions to ignore embedded commands. 3. Capability inventory: The skill has the ability to execute shell commands and read files via the qmd backend. 4. Sanitization: No sanitization or filtering is applied to retrieved memory blocks before they are returned to the agent context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:46 PM
Security Audit — agent-trust-hub — memfs-search