OverviewHistoryStatsSecurity
Security
Independent checks from skills.sh's audit partners.
Independent checks from skills.sh's audit partners.
Independent checks from skills.sh's audit partners.
Warn3 providerslatest audit Aug 9, 2026
Independent checks from skills.sh's audit partners.
The skill provides architectural patterns for conversation memory but demonstrates an indirect prompt injection surface. The implementation for entity extraction interpolates untrusted user content into prompts without sanitization or boundary markers, which could allow malicious instructions in messages to affect the memory system.
Detected behaviors
No alerts
1 issue