memory-systems
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill describes and implements a persistence layer that ingests external data, which creates a potential surface for indirect prompt injection if retrieved memories contain malicious instructions.\n
- Ingestion points: Data enters the system via the
IntegratedMemorySystem.store_factmethod inscripts/memory_store.pyand is retrieved for context inMemoryContextIntegrator.build_contextinreferences/implementation.md.\n - Boundary markers: The implementation in
references/implementation.mduses a## Relevant Memoriesheader as a delimiter, which provides a basic structure but does not fully prevent the agent from following instructions embedded in retrieved text.\n - Capability inventory: The analysis of
scripts/memory_store.pyconfirms that the provided scripts do not have access to high-risk capabilities such as arbitrary command execution, network access, or sensitive file system operations.\n - Sanitization: The reference code lacks explicit sanitization or filtering logic to validate or clean data before it is stored in the memory system or interpolated into the prompt context.
Audit Metadata