conversation-memory

Pass

Audited by Gen Agent Trust Hub on Jun 26, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill describes a memory management system that processes untrusted user input, stores it as persistent memories or entities, and subsequently interpolates this content into future prompt contexts. This architecture creates an inherent surface for indirect prompt injection attacks.
  • Ingestion points: Untrusted user input from message.content is ingested and processed in SKILL.md within the addMessage, extractAndStore, and promptWithMemory methods.
  • Boundary markers: The prompt construction logic provided in promptWithMemory uses Markdown headers (e.g., ## User Context, ## Relevant past interactions) but lacks explicit delimiters or instructions directing the LLM to ignore or treat retrieved memories as untrusted data.
  • Capability inventory: The skill provides logical patterns for memory storage and retrieval but does not include scripts or tools that execute subprocesses, file system modifications, or network operations.
  • Sanitization: The provided code snippets do not include logic for sanitizing or validating facts and entities extracted from user messages before they are stored in the persistent memory layers.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 26, 2026, 10:23 PM