memory-systems

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The memory architecture designed by the skill ingests external data into a persistent store and later retrieves it for injection into the agent's context. This creates a potential surface where malicious instructions embedded in the ingested data could influence agent behavior upon retrieval. \n
  • Ingestion points: scripts/memory_store.py (via store_fact) and references/implementation.md (via cognee.add and VectorStore.add).\n
  • Boundary markers: The MemoryContextIntegrator in references/implementation.md uses a ## Relevant Memories header but does not provide explicit instructions to the agent to disregard any embedded commands or formatting within the retrieved memories.\n
  • Capability inventory: The skill provides logic for semantic and graph-based retrieval but does not perform execution of the retrieved data; the primary risk is influence over the LLM's next-step generation.\n
  • Sanitization: No sanitization, validation, or escaping of the ingested content is performed before storage or retrieval in the provided implementation examples.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 05:10 AM
Security Audit — agent-trust-hub — memory-systems