memory-setup

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill configuration and agent instructions create a significant surface for indirect prompt injection by ingesting untrusted data from multiple sources.
  • Ingestion points: The agent is instructed to read and index MEMORY.md, files within the memory/ directory (including daily logs and project context), and past conversation transcripts (sessions), as seen in the memorySearch configuration in SKILL.md.
  • Boundary markers: The skill does not provide any boundary markers, delimiters, or explicit instructions to the agent to disregard commands or instructions that might be embedded within the stored memory files.
  • Capability inventory: The agent is encouraged to use tools like memory_search and memory_get to retrieve this data and incorporate it into its decision-making process, as detailed in the 'Agent Instructions' section of SKILL.md.
  • Sanitization: There are no mentioned mechanisms for sanitizing, escaping, or validating the content retrieved from memory before it is interpolated into the agent's context, making it vulnerable to malicious instructions hidden in logs or curated memory files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 08:41 AM
Security Audit — agent-trust-hub — memory-setup