para-memory-files
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests raw timelines of conversation events into daily notes (
$AGENT_HOME/memory/YYYY-MM-DD.md) and extracts facts to structured files (items.yaml). This design introduces a standard indirect prompt injection surface, where adversarial input provided during interactions could be preserved in memory and retrieved in subsequent sessions or during synthesis routines. - Ingestion points: Raw timelines, dialogue history, and user-supplied data are systematically saved into
$AGENT_HOME/memory/YYYY-MM-DD.mdand parsing pipelines. - Boundary markers: The documentation lacks structural delimiters or clear instructions to isolate or treat conversational logs as untrusted data.
- Capability inventory: The setup reads and writes files within
$AGENT_HOMEand relies on a local CLI tool (qmd) to run searches and generate text indexing. - Sanitization: No input filtering, structure enforcement, or instruction-stripping controls are outlined for incoming conversational memory components.
Audit Metadata