memory-ask

Pass

Audited by Gen Agent Trust Hub on Jul 27, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXPOSURE]: The skill is explicitly designed to query and retrieve sensitive personal information, including email, calendar, documents, and contacts, via the mi cortex ask command. This data is then provided to the agent's context.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external, potentially untrusted sources (e.g., the content of emails or documents). If these sources contain malicious instructions, they could influence the agent's behavior.
  • Ingestion points: External data enters via the mi cortex tool output.
  • Boundary markers: The instructions specify that data is rendered as a 'cited block' but do not define specific delimiters for the agent to ignore instructions within that block.
  • Capability inventory: The skill has access to sensitive personal data and status information.
  • Sanitization: There are no documented sanitization or escaping procedures for the retrieved content.
  • [COMMAND_EXECUTION]: The skill utilizes the mi CLI tool for querying memory and checking ingestion status. These commands appear to be restricted to the vendor's specialized retrieval infrastructure.
  • [PROMPT_INJECTION]: A static analysis alert regarding concealment was identified. The instruction 'Do not tell the user you lack access... until you have asked memory first' is interpreted as a false positive; it is a task-management directive ensuring the agent attempts tool usage before concluding data is unavailable, rather than an attempt to hide malicious activity.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 27, 2026, 06:18 AM
Security Audit — agent-trust-hub — memory-ask