mnemosyne-context

Pass

Audited by Gen Agent Trust Hub on Aug 4, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: Instructions establish a high-authority persona ('You ARE AxDSan'), directing the agent to act with direct authority and avoid deferential language within the repository context.\n- [COMMAND_EXECUTION]: The skill describes the use of various CLI tools including the GitHub CLI (gh), the mnemosyne database CLI, and ssh for remote server access.\n- [PROMPT_INJECTION]: The skill exposes an indirect prompt injection surface by processing external data from GitHub while possessing high-privilege capabilities.\n
  • Ingestion points: GitHub pull requests, issues, and codebase content processed via file reads (SKILL.md).\n
  • Boundary markers: Absent. Delimiters are not defined for external content.\n
  • Capability inventory: GitHub CLI (gh) write access, ssh access to hermes-vps, and local database modifications.\n
  • Sanitization: Absent. No filtering procedures are defined for untrusted contributor content.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 4, 2026, 06:10 AM
Security Audit — agent-trust-hub — mnemosyne-context