project-memory

Pass

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to read and automatically apply context from files stored in the .agents/memory/ directory of a project repository. This creates a vulnerability where malicious instructions committed to these files (e.g., by a third-party contributor or in a compromised repository) could steer the agent's future actions.
  • Ingestion points: The agent is instructed to read MEMORY.md and linked topic files (feedback_*.md, *_progress.md, *_config.md) at the start of non-trivial tasks in SKILL.md.
  • Boundary markers: The instructions do not define delimiters or specific warnings to ignore potentially malicious embedded instructions within the memory files.
  • Capability inventory: The agent maintains the ability to read and write files within the project repository to manage these memory notes.
  • Sanitization: No sanitization or validation of the stored memory content is mentioned; the skill explicitly directs the agent to "apply learnings automatically."
  • [COMMAND_EXECUTION]: The skill includes instructions for the agent to execute shell commands such as ls to check for the existence of memory directories and suggests using make test for project workflows. While these are standard developer operations, they reflect the capability to execute commands based on the project context defined in the memory files.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 18, 2026, 05:27 AM
Security Audit — agent-trust-hub — project-memory