persistent-memory

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [Indirect Prompt Injection] (LOW): The skill's core functionality of storing and retrieving context creates an inherent risk for indirect prompt injection. Ingestion points: The 'pmem add' command in 'SKILL.md' allows the storage of arbitrary text. Boundary markers: No delimiters or 'ignore' instructions are documented for the retrieval of memories. Capability inventory: The skill executes local CLI scripts and integrates retrieved strings back into the agent's active context. Sanitization: No input sanitization or validation mechanisms are visible in the provided configuration files.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 05:15 PM