ov-experience-memory
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and act upon 'Experience' content retrieved from external OpenViking URIs. If these stored memories contain adversarial instructions, the agent might follow them during high-stakes operations.
- Ingestion points: The retrieval workflow in
SKILL.mdfetches content from theviking://~/memories/experiencesroot using environment-specific tools likefind,search, andread. - Boundary markers: The skill includes explicit instructions to prioritize system/developer rules and user requests over Experience data. It also warns to ignore unsafe or conflicting guidance.
- Capability inventory: The skill is used during 'executable, multi-step, or tool-based work' such as coding, data changes, configuration, and deployment, which involves significant system access.
- Sanitization: There are no technical sanitization or validation steps mentioned for the retrieved content, beyond the agent's internal reasoning and the established priority order.
Audit Metadata