memory-systems
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The memory architecture designed by the skill ingests external data into a persistent store and later retrieves it for injection into the agent's context. This creates a potential surface where malicious instructions embedded in the ingested data could influence agent behavior upon retrieval. \n
- Ingestion points:
scripts/memory_store.py(viastore_fact) andreferences/implementation.md(viacognee.addandVectorStore.add).\n - Boundary markers: The
MemoryContextIntegratorinreferences/implementation.mduses a## Relevant Memoriesheader but does not provide explicit instructions to the agent to disregard any embedded commands or formatting within the retrieved memories.\n - Capability inventory: The skill provides logic for semantic and graph-based retrieval but does not perform execution of the retrieved data; the primary risk is influence over the LLM's next-step generation.\n
- Sanitization: No sanitization, validation, or escaping of the ingested content is performed before storage or retrieval in the provided implementation examples.
Audit Metadata