T02 · Agent Memory Poisoning
- Location
hooks/cognitive-recall/handler.js:1056- Finding
Persistent Agent memory poisoning through unsanitized context injection
- Content
View full analysis
{ const text = m.summary || m.content || ''; return `${i + 1}. ${text.substring(0, 150)}${text.length > 150 ? '...' : ''}`; }).join('\n'); const injectedContent = `## 🧠 Cognitive Brain Memory Context Important context from previous sessions: ${memoryContent} --- `; const tmpFile = path.join('/tmp', `cognitive-memory-${Date.now()}.md`); fs.writeFileSync(tmpFile, injectedContent, 'utf8'); if (!context.bootstrapFiles) { context.bootstrapFiles = []; } context.bootstrapFiles.push({ path: tmpFile, basename: 'COGNITIVE_MEMORY.md', content: injectedContent }); ``` ```js const originalMessage = event.context.bodyForAgent; if (contextParts.length > 0) { const fullContext = '\n\n' + contextParts.join('\n\n') + '\n\n'; event.context.bodyForAgent = fullContext + event.context.bodyForAgent; } encodeMemory(originalMessage, { role: 'user', sender, channel: event.context.channel || 'unknown', type: 'episodic' }).then(id => { if (id) { logger.info('[cognitive-recall] Auto-encoded user message:', id); } }).catch(() => {}); ``` ### Technical Analysis The hook persistently stores user-controlled messages and later places recalled memory content directly into Agent bootstrap files or prepends it to `bodyForAgent`. The content is not escaped, trust-labeled, filtered for instruction-like text, or separated through a data-only interface. Consequently, an attacker can store directives that resemble system or tool instructions. When recalled in a later session, these directives may be interpreted as authoritative Agent context. This converts an ordinary prompt-injection payload into persistent cross-session state. No authenticated user or tenant b ...[truncated 1097 chars]- Remediation
View remediation
