T02 · Agent Memory Poisoning
- Location
SKILL.md:24- Finding
Untrusted conversation content can be promoted into persistent Agent instructions
- Content
View full analysis
/` 3. **Write SKILL.md**: Use standard skill format with YAML frontmatter 4. **Update learning**: Set status to `promoted_to_skill`, add `Skill-Path` 5. **Publish to ClawHub**: Share with community ``` `SKILL.md:129-139`: ```markdown Review `.learnings/` at natural breakpoints: - Before starting a new major task - After completing a feature - When working in an area with past learnings - Weekly during active development ### Review Actions - Resolve fixed items - Promote applicable learnings - Link related entries - Escalate recurring issues - Extract recurring patterns as skills ``` `SKILL.md:151`: ```markdown 7. **Promote aggressively** - if in doubt, add to CLAUDE.md or .github/copilot-instructions.md ``` ### Technical Analysis The Skill instructs the Agent to record user corrections, error output, and other conversation-derived material in persistent `.learnings/` files. It then directs the Agent to promote those records into reusable Skills and persistent Agent instruction files such as `CLAUDE.md` and `.github/copilot-instructions.md`. Conversation content is an untrusted input bo ...[truncated 2715 chars]- Remediation
View remediation
