zep
Pass
Audited by Gen Agent Trust Hub on Jun 14, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches memory context and conversation history from the Zep API at api.getzep.com.
- [COMMAND_EXECUTION]: Employs curl to interact with API endpoints for managing user data and session history.
- [DATA_EXFILTRATION]: Transmits conversation messages and metadata to the external Zep service for long-term storage and retrieval.
- [PROMPT_INJECTION]: The skill instructs the agent to inject retrieved memory context into its system prompt, creating a surface for indirect prompt injection.
- Ingestion points: Memory retrieval from api.getzep.com in SKILL.md.
- Boundary markers: None specified.
- Capability inventory: Command execution via curl in SKILL.md.
- Sanitization: None mentioned.
Audit Metadata