mem-file-scan

Pass

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands using find to discover files modified within a specific date range. While this is a standard use of agent capabilities for file management, it involves direct interaction with the system shell.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted data from local Markdown files, which creates a potential surface for indirect prompt injection if those files contain malicious instructions.
  • Ingestion points: The agent uses the find command to locate files and a Read tool to ingest the content of any .md file in the user's vault (SKILL.md, Step 2 and Step 4).
  • Boundary markers: There are no explicit boundary markers or specific instructions (e.g., XML tags or delimiters) defined to separate ingested file content from the agent's internal instructions.
  • Capability inventory: The agent has the capability to execute shell commands (bash), read local files, and invoke other skills like mem-record to write data to the memory system.
  • Sanitization: The instructions do not specify any sanitization, filtering, or validation of the content read from the files before it is processed by the LLM for summary generation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 21, 2026, 02:09 AM