recall
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill retrieves and displays narratives, titles, and observations from past sessions stored in
agentmemoryvia thememory_smart_searchtool. - Ingestion points: The skill processes results from the
memory_smart_searchtool (as defined inSKILL.md), which includes untrusted data from provenance channels likeimport,shared, and even previoususeroragentsessions. - Capability inventory: The agent uses
memory_smart_searchto fetch this data and then interprets the narrative content to present it to the user. - Boundary markers: The instructions in
SKILL.mdandEXAMPLES.mdshow the content being presented directly (e.g., "Yes. In session 7f3a9c21 you decided to...") without the use of XML tags, markdown blocks, or explicit "ignore embedded instructions" warnings to prevent the LLM from following commands hidden in the recalled text. - Sanitization: No sanitization, validation, or filtering of the narrative content is described before the content is placed back into the agent's context.
- [PROMPT_INJECTION]: The skill interpolates user-supplied input directly into the primary instruction context using the
$ARGUMENTSplaceholder inSKILL.md("The user wants to recall past context about: $ARGUMENTS"). While this is standard for many agent platforms, it provides a direct surface for users to attempt to override skill instructions if the platform does not provide underlying protection.
Audit Metadata