ov-experience-memory

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and act upon 'Experience' content retrieved from external OpenViking URIs. If these stored memories contain adversarial instructions, the agent might follow them during high-stakes operations.
  • Ingestion points: The retrieval workflow in SKILL.md fetches content from the viking://~/memories/experiences root using environment-specific tools like find, search, and read.
  • Boundary markers: The skill includes explicit instructions to prioritize system/developer rules and user requests over Experience data. It also warns to ignore unsafe or conflicting guidance.
  • Capability inventory: The skill is used during 'executable, multi-step, or tool-based work' such as coding, data changes, configuration, and deployment, which involves significant system access.
  • Sanitization: There are no technical sanitization or validation steps mentioned for the retrieved content, beyond the agent's internal reasoning and the established priority order.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 09:09 PM
Security Audit — agent-trust-hub — ov-experience-memory