gsd-mempalace-recall

Pass

Audited by Gen Agent Trust Hub on Jul 22, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill uses terminology typical of prompt injection attacks, stating 'This prompt was injected into your context'. While this appears to be a workflow instruction intended to optimize token usage by preventing the agent from re-reading the file, the use of deceptive phrasing is noted.
  • [COMMAND_EXECUTION]: The skill executes vendor-specific CLI tools ('mempalace search', 'mempalace wake-up') via the Bash tool to interact with a local memory backend. These commands are consistent with the skill's stated purpose of recalling information from 'open-gsd' infrastructure.
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it ingests data from a memory storage system and incorporates it into agent-consumed planning files.
  • Ingestion points: Memory retrieval results from the 'mempalace' CLI and context from 'CONTEXT.md' (SKILL.md).
  • Boundary markers: No explicit delimiters or instructions are provided to the agent to treat the retrieved memory data as untrusted content (SKILL.md).
  • Capability inventory: The skill utilizes 'Write' for file modification and 'Bash' for command execution, allowing the ingested data to influence file outputs (SKILL.md).
  • Sanitization: The instructions direct the agent to 'distil' the findings into specific categories (decisions, patterns, surprises), which provides a layer of summarization rather than direct interpolation.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 22, 2026, 11:09 PM
Security Audit — agent-trust-hub — gsd-mempalace-recall