review-evidence-and-memory
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external evidence and research data, which creates a potential surface for indirect prompt injection.
- Ingestion points: Untrusted data enters the agent context via evidence sources handled by the
evidence_searchandevidence_reopentools (SKILL.md). - Boundary markers: While explicit text delimiters are not defined, the skill mandates logical gates such as 'ACCEPTED' status and protocol verification.
- Capability inventory: The skill has the capability to write to durable storage via the
memory_promoteandmemory_proposetools (SKILL.md). - Sanitization: Significant mitigations are present; instructions require explicit human approval before memory promotion and the 'references/memory-policy.md' explicitly forbids storing secrets, employer material, or unverified claims.
Audit Metadata