skills/yeluyang/skills/memory/Gen Agent Trust Hub

memory

Pass

Audited by Gen Agent Trust Hub on Apr 10, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes untrusted data from the repository (such as README files, code comments, and existing documentation) and summarizes it into a canonical memory file. Malicious instructions embedded in these source files could be carried over into the generated output, affecting the behavior of AI agents that consume the memory files in subsequent sessions.
  • Ingestion points: Project manifests (package.json, pyproject.toml, go.mod, etc.), README.md, sample source files, and existing memory files (AGENTS.md, CLAUDE.md).
  • Boundary markers: The instructions do not specify the use of delimiters or explicit warnings to prevent the agent from obeying instructions found within the ingested repository content.
  • Capability inventory: The skill requires file system search, multi-file read access, and the ability to write or update root-level documentation files.
  • Sanitization: There is no mention of sanitizing or validating ingested text to remove potential malicious instructions before synthesizing the final documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 10, 2026, 02:44 AM
Security Audit — agent-trust-hub — memory