memory-setup
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill configuration and agent instructions create a significant surface for indirect prompt injection by ingesting untrusted data from multiple sources.
- Ingestion points: The agent is instructed to read and index
MEMORY.md, files within thememory/directory (including daily logs and project context), and past conversation transcripts (sessions), as seen in thememorySearchconfiguration inSKILL.md. - Boundary markers: The skill does not provide any boundary markers, delimiters, or explicit instructions to the agent to disregard commands or instructions that might be embedded within the stored memory files.
- Capability inventory: The agent is encouraged to use tools like
memory_searchandmemory_getto retrieve this data and incorporate it into its decision-making process, as detailed in the 'Agent Instructions' section ofSKILL.md. - Sanitization: There are no mentioned mechanisms for sanitizing, escaping, or validating the content retrieved from memory before it is interpolated into the agent's context, making it vulnerable to malicious instructions hidden in logs or curated memory files.
Audit Metadata