memory
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's primary function is storing and retrieving arbitrary text data through
rememberandrecalltools. This introduces a vulnerability surface where a user or an external process could feed malicious instructions into the agent's memory. When the agent later retrieves these 'memories,' the LLM may treat the stored text as a new set of instructions, potentially bypassing original system constraints.
Audit Metadata