persistent-memory

Pass

Audited by Gen Agent Trust Hub on Jun 19, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill establishes an indirect prompt injection surface by instructing the agent to store and retrieve conversation context as 'memory' without implementing security boundaries.
  • [PROMPT_INJECTION]: Ingestion points: Conversation history and user-provided context are processed into storage via the filesystem and GitHub (as specified in the mcp-servers field of SKILL.md).
  • [PROMPT_INJECTION]: Boundary markers: There are no instructions to use delimiters or to disregard embedded commands when retrieving stored memory content.
  • [PROMPT_INJECTION]: Capability inventory: The skill is configured with high-privilege capabilities including the Bash tool and access to the Docker and GitHub MCP servers, which increases the potential impact of successful prompt injection.
  • [PROMPT_INJECTION]: Sanitization: No procedures for validating, escaping, or sanitizing stored or retrieved content are defined in the skill instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 19, 2026, 05:22 AM
Security Audit — agent-trust-hub — persistent-memory