session-dream

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains a vulnerability surface for indirect prompt injection. It processes the current conversation transcript (untrusted input) and instructs the agent to extract and persist 'high-value' findings into permanent project memory files.
  • Ingestion points: The skill ingests the entire active conversation transcript during the 'Gather signal' phase.
  • Boundary markers: The instructions lack defined delimiters or specific warnings to ignore instructions that might be embedded within the conversation text being distilled.
  • Capability inventory: The skill utilizes file-read and file-write capabilities across multiple files (MEMORY.md and various topic files).
  • Sanitization: No sanitization, escaping, or validation logic is defined to prevent malicious or deceptive content from being written into the project's persistent memory base.
  • [COMMAND_EXECUTION]: The skill directs the agent to perform extensive filesystem operations, including reading project indexes and writing/updating multiple markdown files to manage the memory distillation process.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 05:03 AM
Security Audit — agent-trust-hub — session-dream