agent-memory

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructions specify that if an AGENTS.md file exists in the repository root, it will be added to the agent's context automatically. This creates a vulnerability where malicious instructions could be placed in this file (e.g., by an untrusted contributor in a public repository) to influence the agent's behavior when the file is loaded.
  • Ingestion points: AGENTS.md located in the repository root (referenced in SKILL.md and README.md).
  • Boundary markers: No explicit delimiters or instructions to treat the file content as untrusted are defined; the content is "added to your context automatically."
  • Capability inventory: The agent possesses capabilities to read/write files and execute repository-specific commands.
  • Sanitization: The instructions lack any requirement for the agent to sanitize, validate, or filter the content retrieved from the AGENTS.md file.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 06:41 AM
Security Audit — agent-trust-hub — agent-memory