remember
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted user input via the
$ARGUMENTSvariable and saves it directly to a long-term storage tool (memory_save). - Ingestion points: User input is captured via
$ARGUMENTSinSKILL.mdand passed to thecontentfield of thememory_savetool. - Boundary markers: The instructions lack explicit boundary markers or directives for the agent to treat retrieved memories as non-executable data, increasing the risk that a stored payload could influence future agent behavior during a
recalloperation. - Capability inventory: While this specific skill only utilizes the
memory_savetool, the agent environment typically includes file system access, network operations, and command execution capabilities that could be targeted by successful injection. - Sanitization: There is no evidence of sanitization, validation, or escaping of the user-provided content before it is stored in the long-term memory system.
Audit Metadata