remember
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests arbitrary user text and stores it in long-term memory with high confidence. While this is the intended functionality, it creates a surface where unverified content could persist in the agent's knowledge base.\n- Ingestion points: User-provided text in SKILL.md Step 1.\n- Boundary markers: None explicitly defined in the instructions for the stored text.\n- Capability inventory: The skill utilizes the 'add_memory' tool for persistent storage and 'get_event_status' for confirmation.\n- Sanitization: The instructions do not specify any validation or sanitization of the input text before storage.
Audit Metadata