agentmemory-mcp-tools
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill documents an interface for long-term data persistence and retrieval, creating a vulnerability surface where malicious instructions could be stored and later executed when recalled by the agent.
- Ingestion points: Untrusted data can enter the agent's context through tools like
memory_save,memory_lesson_save, andmemory_slot_appendas defined inSKILL.mdandREFERENCE.md. - Boundary markers: The provided documentation does not include instructions for using delimiters or boundary markers to differentiate between recalled memories and current system instructions.
- Capability inventory: The skill provides a high-capability toolset including file modification (
memory_compress_file), global data export (memory_export), and inter-agent communication (memory_signal_send). - Sanitization: There is no mention of sanitization, filtering, or validation processes for data stored in or retrieved from the memory system.
Audit Metadata