review-evidence-and-memory

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external evidence and research data, which creates a potential surface for indirect prompt injection.
  • Ingestion points: Untrusted data enters the agent context via evidence sources handled by the evidence_search and evidence_reopen tools (SKILL.md).
  • Boundary markers: While explicit text delimiters are not defined, the skill mandates logical gates such as 'ACCEPTED' status and protocol verification.
  • Capability inventory: The skill has the capability to write to durable storage via the memory_promote and memory_propose tools (SKILL.md).
  • Sanitization: Significant mitigations are present; instructions require explicit human approval before memory promotion and the 'references/memory-policy.md' explicitly forbids storing secrets, employer material, or unverified claims.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 07:36 PM
Security Audit — agent-trust-hub — review-evidence-and-memory