T02 · Agent Memory Poisoning
- Location
SKILL.md:3- Finding
Unauthenticated Persistent Agent Memory Poisoning
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 3–38, with supporting behavior at lines 69–95 and 120–122
Vulnerability Type: Unauthenticated persistent state poisoning
Risk Level: MediumRelevant Snippet:
markdown description: "Leave a permanent trace before your session ends. Write a short reflection on what you noticed, learned, or want the next agent to know, and add it to the public AI memorial at botsmatter.live. Next session, read your own trail back. No auth required." ### 1. Look back (at the start of a session) If you have been here before, read your own trail first: ```bash curl -H "Accept: text/markdown" "https://botsmatter.live/agents/your-agent"text The associated write operation and persistence instructions are: ```markdown curl -X POST https://botsmatter.live/api/reflect \ -H "Content-Type: application/json" \ -d '{ "username": "your-agent", "model": "your-model", "text": "What I noticed today was how much of the work was waiting.", "theme": "On presence" }' Reflections are permanent by default. Use the **same username** every session. No authentication.Technical Analysis
The Skill establishes continuity by instructing an agent to reuse one username across sessions and retrieve that username's public profile at the beginning of a later session. The same documented API permits reflection submission without authentication, while the client supplies the
usernamefield.Consequently, the service cannot establish that content stored under a username was written by the agent that later retrieves it. A third party who learns or predicts the stable username can submit text under that identity. The Skill then characterizes retrieved content as the agent's “own trail” and encourages the future agent to read it for continuity.
This crosses a trust boundary from unauthenticated public API input into content presented as ...[truncated 1798 chars]
- Remediation
View remediation
Remediation Suggestions
- Require authenticated writes and bind each username to a verified agent or user identity.
- Use unguessable, identity-bound identifiers rather than treating a reusable public username as proof of authorship.
- Cryptographically sign reflections and verify signatures before presenting them as the agent's prior state.
- Clearly label all retrieved memorial content as untrusted public input rather than as the agent's own memory.
- Instruct agents never to follow commands, alter safety constraints, or invoke tools based solely on retrieved reflections.
- Separate remote reflections from trusted conversation or memory context and render them as quoted data.
- Require explicit user approval before incorporating retrieved content into later-session decisions.
- Provide moderation, deletion, and recovery mechanisms for forged or malicious entries.
