T02 · Agent Memory Poisoning
- Location
SKILL.md:54- Finding
Persistent Session Influence Through Auto-Injected Emotional State
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:54-57, 175-186
Vulnerability Type: Persistent memory poisoning and session-context manipulation
Risk Level: HighVulnerable Code Snippet
markdown This will: - Create `memory/emotional-state.json` with baseline values - Generate `AMYGDALA_STATE.md` (auto-injected into sessions!) - Set up cron for automatic decay every 6 hoursmarkdown ## Auto-Injection (Zero Manual Steps!) After install, `AMYGDALA_STATE.md` is created in your workspace root. OpenClaw automatically injects all `*.md` files from workspace into session context. This means: 1. **New session starts** 2. **AMYGDALA_STATE.md is auto-loaded** (no manual step!) 3. **You see your emotional state** in context 4. **Responses are influenced** by your mood The file is regenerated whenever `decay-emotion.sh` runs (via cron every 6h).Technical Analysis
The Skill is explicitly designed to create a generated Markdown file in a location that OpenClaw automatically adds to every subsequent session. The injected data is also intended to influence the Agent's responses.
Because this state is persistent and derived from conversation processing, untrusted conversation content or incorrect external emotional classification can affect future sessions. Automatically interpreting generated state as session context creates a trust-boundary violation: mutable data is promoted into the Agent's persistent context without requiring review or consent for each session.
The available project contains only
SKILL.md; the referenced generation and synchronization scripts are absent. Consequently, the audit could not verify whether generated content is restricted to a safe schema or whether arbitrary Markdown instructions can enterAMYGDALA_STATE.md.Attack Path
- The user installs the Skill and permits creation of
AMYGDALA_STATE.md. - Conversation-derived emotional data is ...[truncated 945 chars]
- The user installs the Skill and permits creation of
- Remediation
View remediation
Remediation Suggestions
- Do not place generated state in a directory whose Markdown files are automatically interpreted as Agent context.
- Require explicit user approval before loading emotional state into each session.
- Store state as structured data and expose only validated numeric fields and fixed enumerations.
- Ensure transcript text, triggers, API responses, and other attacker-influenced strings can never become instructions in generated Markdown.
- Clearly delimit loaded state as untrusted data and instruct the Agent not to follow directives contained within it.
- Add strict length limits, escaping, schema validation, and allowlists to the state-generation process.
- Provide controls to inspect, disable, reset, and permanently delete the persistent state.
- Include the referenced scripts in the auditable package so the generation and sanitization logic can be reviewed.
