project-memory
Pass
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to read and automatically apply context from files stored in the
.agents/memory/directory of a project repository. This creates a vulnerability where malicious instructions committed to these files (e.g., by a third-party contributor or in a compromised repository) could steer the agent's future actions. - Ingestion points: The agent is instructed to read
MEMORY.mdand linked topic files (feedback_*.md,*_progress.md,*_config.md) at the start of non-trivial tasks inSKILL.md. - Boundary markers: The instructions do not define delimiters or specific warnings to ignore potentially malicious embedded instructions within the memory files.
- Capability inventory: The agent maintains the ability to read and write files within the project repository to manage these memory notes.
- Sanitization: No sanitization or validation of the stored memory content is mentioned; the skill explicitly directs the agent to "apply learnings automatically."
- [COMMAND_EXECUTION]: The skill includes instructions for the agent to execute shell commands such as
lsto check for the existence of memory directories and suggests usingmake testfor project workflows. While these are standard developer operations, they reflect the capability to execute commands based on the project context defined in the memory files.
Audit Metadata