memory-sync

Pass

Audited by Gen Agent Trust Hub on May 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes conversation history to update memory files, creating a surface for indirect prompt injection (Category 8). This is mitigated by a mandatory Evidence Chain: 1. Ingestion: Session conversation analyzed in Step 2. 2. Boundary markers: Uses specific markdown structures and a dedicated approval step. 3. Capabilities: Employs the Edit tool for file writes and bash for timestamping. 4. Sanitization: Step 3 requires explicit user approval of all proposed changes before they are applied, preventing autonomous exploitation.
  • [COMMAND_EXECUTION]: Step 4.5 executes a bash command to record a Unix timestamp in a synchronization file. This is a low-risk, local operation used for internal bookkeeping and does not accept untrusted input or escalate privileges.
Audit Metadata
Risk Level
SAFE
Analyzed
May 18, 2026, 01:33 PM