mem-file-scan
Pass
Audited by Gen Agent Trust Hub on Aug 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands using
findto discover files modified within a specific date range. While this is a standard use of agent capabilities for file management, it involves direct interaction with the system shell. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted data from local Markdown files, which creates a potential surface for indirect prompt injection if those files contain malicious instructions.
- Ingestion points: The agent uses the
findcommand to locate files and aReadtool to ingest the content of any.mdfile in the user's vault (SKILL.md, Step 2 and Step 4). - Boundary markers: There are no explicit boundary markers or specific instructions (e.g., XML tags or delimiters) defined to separate ingested file content from the agent's internal instructions.
- Capability inventory: The agent has the capability to execute shell commands (
bash), read local files, and invoke other skills likemem-recordto write data to the memory system. - Sanitization: The instructions do not specify any sanitization, filtering, or validation of the content read from the files before it is processed by the LLM for summary generation.
Audit Metadata