skills/mem0ai/mem0/status/Gen Agent Trust Hub

status

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill accesses the sensitive file path ~/.pi/agent/mem0-config.json and the MEM0_API_KEY environment variable to verify configuration. It also instructs the agent to display the first six characters of the API key in the status output, which constitutes a partial credential exposure.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data retrieved from the mem0_memory tool during connectivity and quality checks, creating a surface for indirect prompt injection if the stored memories contain malicious instructions.
  • Ingestion points: Data is ingested from the mem0_memory tool via search and get_all actions as described in SKILL.md.
  • Boundary markers: No delimiters or instructions to ignore embedded content are specified for the memory data processing steps.
  • Capability inventory: The skill utilizes the mem0_memory tool for adding, searching, and retrieving memories.
  • Sanitization: There is no mention of sanitization, validation, or filtering of the retrieved memory content before it is processed by the agent for quality analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 12:58 AM
Security Audit — agent-trust-hub — status