agent-memory
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructions specify that if an
AGENTS.mdfile exists in the repository root, it will be added to the agent's context automatically. This creates a vulnerability where malicious instructions could be placed in this file (e.g., by an untrusted contributor in a public repository) to influence the agent's behavior when the file is loaded. - Ingestion points:
AGENTS.mdlocated in the repository root (referenced inSKILL.mdandREADME.md). - Boundary markers: No explicit delimiters or instructions to treat the file content as untrusted are defined; the content is "added to your context automatically."
- Capability inventory: The agent possesses capabilities to read/write files and execute repository-specific commands.
- Sanitization: The instructions lack any requirement for the agent to sanitize, validate, or filter the content retrieved from the
AGENTS.mdfile.
Audit Metadata