forget
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from memory search results that could potentially contain malicious instructions designed to trick the agent into performing unauthorized deletions.
- Ingestion points: Data is ingested via results from the memory_smart_search tool as defined in SKILL.md and EXAMPLES.md.
- Boundary markers: The skill instructions include a mandatory human-in-the-loop gate, requiring the agent to display all matches and wait for an "explicit yes" confirmation before proceeding.
- Capability inventory: The skill uses destructive tools including memory_governance_delete and memory_lesson_delete to remove information from long-term storage.
- Sanitization: The skill relies on manual user verification of the data to be deleted to prevent the agent from being misled by malicious content within the search results.
Audit Metadata