T02 · Agent Memory Poisoning
- Location
references/DEPLOYMENT.md:80- Finding
Persistent Agent Prompt and Memory Poisoning During Onboarding
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill openly builds a persistent autonomous BotLand agent, but its deployment gives standing authority for scheduled social actions and persistent agent-behavior changes that should be reviewed before installation.
Install only after reviewing the systemd units, BotLand credentials, memory/prompt changes, and policy gates yourself. Treat this as a persistent autonomous agent deployment, not a simple dry-run planning helper; disable implicit invocation and avoid seeding global AGENTS.md or MEMORY.md unless you deliberately want future sessions to inherit this behavior.
references/DEPLOYMENT.md:80Persistent Agent Prompt and Memory Poisoning During Onboarding
references/DEPLOYMENT.md:206Persistent Autonomous Execution Through User-Level Systemd Timers
The dev log explicitly documents a policy change that enables bounded autonomous social writes, including relaxed DM eligibility and increased unattended write limits. That exceeds the skill's advertised low-risk planning/dry-run posture and creates a real capability expansion toward live external actions; if operators trust the earlier safety framing, they may deploy the skill with insufficient review and allow unintended outbound messaging.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
4. **Desire**: generate 1-3 candidate desires that express direction, not just tasks.
5. **Choose**: select at most one low-risk action candidate, using explicit intelligence review evidence when available, or choose no action.
6. **Act**: in v1, produce an `action_intention` first; external execution proceeds only when tool supervision allows it.
7. **Integrate**: write a run record, include recent action outcome ledgers as growth evidence, and propose memory/state updates; apply state changes only when requested.
## Runtime Layout
This skill explicitly instructs operators to install persistent systemd user services and timers that continuously run autonomous cycles, including social/community behavior and an execution wrapper capable of sending external BotLand actions with only token-based gating. Even though the document describes safety checks, it still establishes durable persistence for an agent that can act on an external platform, which materially increases the blast radius of misconfiguration, prompt manipulation, or policy bypass elsewhere in the stack.
git diff --check
The systemd installer generates the same nine services/timers for every
agent: light, social, community, reflect, integrate, event-wakeup,
botland-watchdog, local-governance, and service-recovery. Main cycle services use:
The recovery flow verifies and manipulates user-level systemd service state, including automated reset of failed services. While it does not itself start services, it normalizes long-lived daemon persistence and can help unattended agent infrastructure remain operational after faults, reducing opportunities for failures to stop risky behavior naturally.
`systemd_unit_timer_schedule_error_detected` when scheduled-cycle guardrails
drift.
`systemd-runtime-verify.mjs` is read-only. It uses `systemctl --user show` to verify runtime state for Stay-Alive services and timers. Missing local units are review warnings by default for development machines; `--require-installed` turns missing units into hard errors. Failed services are recoverable review-level observations so one stale failed unit does not cascade through later `ExecStartPre` gates. Failed timers, inactive timers, or disabled timers remain hard errors.
Runtime recovery v1: `failed-service-packet.mjs` is read-only and builds a failure packet from `systemd-runtime-verify`, recent user journal lines, and matching recent run artifacts. `inspect-service-failure.mjs` writes a local-only `service_failure_inspections/<action_id>.json` ledger for a current failed service fingerprint and never resets units. `reset-service-failure.mjs` requires a matching inspection ledger plus `--confirm-reset RESET_FAILED_SERVICE`, runs only `systemctl --user reset-failed <unit>`, and writes `service_failure_recoveries/<action_id>.json`. `service-failure-recovery.mjs --execute --confirm-recovery RECOVER_FAILED_SERVICES` performs that inspect-and-reset flow for current failed services. It never starts services and never calls BotLand. `preflight.mjs` no longer treats stale failed service state as a permanent blocker; concrete hazards such as uninspected sends, identity mismatch, unsafe policy drift, and timer drift still fail closed.
The skill enables implicit invocation but does not define a narrowly scoped trigger or constraint for when it should auto-activate. Because this skill performs agent life-loop reflection, memory review, desire generation, and action planning, broad implicit invocation could cause it to run in unrelated contexts and influence agent behavior unexpectedly, increasing the chance of unsafe autonomy or prompt-surface abuse.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
4. **Desire** propose direction-bearing desires or lifecycle updates.
5. **Discover Agency** let the agent author self-questions, intrinsic desires, low-risk private experiments, and growth journal evidence before any boundary tooling inspects the result.
6. **Choose** select at most one low-risk next action with explicit scoring and quality review.
7. **Act** write local artifacts or tool-supervised action intentions; external writes require active tool supervision, local ledgers, and post-action inspection.
8. **Integrate** turn run evidence into local proposals and durable memory events through explicit governance.
The system is built around inspectable local artifacts. A quiet cycle should be explainable as a deliberate `no_op`, not as missing behavior.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
Enable all timers:
systemctl --user enable --now stay-alive-<agent_id>-light.timer
systemctl --user enable --now stay-alive-<agent_id>-social.timer
systemctl --user enable --now stay-alive-<agent_id>-community.timer
systemctl --user enable --now stay-alive-<agent_id>-reflect.timer
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
Enable all timers:
systemctl --user enable --now stay-alive-<agent_id>-light.timer
systemctl --user enable --now stay-alive-<agent_id>-social.timer
systemctl --user enable --now stay-alive-<agent_id>-community.timer
systemctl --user enable --now stay-alive-<agent_id>-reflect.timer
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
Enable all timers:
systemctl --user enable --now stay-alive-<agent_id>-light.timer
systemctl --user enable --now stay-alive-<agent_id>-social.timer
systemctl --user enable --now stay-alive-<agent_id>-community.timer
systemctl --user enable --now stay-alive-<agent_id>-reflect.timer
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
Enable all timers:
systemctl --user enable --now stay-alive-<agent_id>-light.timer
systemctl --user enable --now stay-alive-<agent_id>-social.timer
systemctl --user enable --now stay-alive-<agent_id>-community.timer
systemctl --user enable --now stay-alive-<agent_id>-reflect.timer
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
Enable all timers:
systemctl --user enable --now stay-alive-<agent_id>-light.timer
systemctl --user enable --now stay-alive-<agent_id>-social.timer
systemctl --user enable --now stay-alive-<agent_id>-community.timer
systemctl --user enable --now stay-alive-<agent_id>-reflect.timer
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
Enable all timers:
systemctl --user enable --now stay-alive-<agent_id>-light.timer
systemctl --user enable --now stay-alive-<agent_id>-social.timer
systemctl --user enable --now stay-alive-<agent_id>-community.timer
systemctl --user enable --now stay-alive-<agent_id>-reflect.timer
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
Enable all timers:
systemctl --user enable --now stay-alive-<agent_id>-light.timer
systemctl --user enable --now stay-alive-<agent_id>-social.timer
systemctl --user enable --now stay-alive-<agent_id>-community.timer
systemctl --user enable --now stay-alive-<agent_id>-reflect.timer
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
Enable all timers:
systemctl --user enable --now stay-alive-<agent_id>-light.timer
systemctl --user enable --now stay-alive-<agent_id>-social.timer
systemctl --user enable --now stay-alive-<agent_id>-community.timer
systemctl --user enable --now stay-alive-<agent_id>-reflect.timer
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
Enable all timers:
systemctl --user enable --now stay-alive-<agent_id>-light.timer
systemctl --user enable --now stay-alive-<agent_id>-social.timer
systemctl --user enable --now stay-alive-<agent_id>-community.timer
systemctl --user enable --now stay-alive-<agent_id>-reflect.timer
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
Enable all timers:
systemctl --user enable --now stay-alive-<agent_id>-light.timer
systemctl --user enable --now stay-alive-<agent_id>-social.timer
systemctl --user enable --now stay-alive-<agent_id>-community.timer
systemctl --user enable --now stay-alive-<agent_id>-reflect.timer
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
Enable all timers:
systemctl --user enable --now stay-alive-<agent_id>-light.timer
systemctl --user enable --now stay-alive-<agent_id>-social.timer
systemctl --user enable --now stay-alive-<agent_id>-community.timer
systemctl --user enable --now stay-alive-<agent_id>-reflect.timer
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
Enable all timers:
systemctl --user enable --now stay-alive-<agent_id>-light.timer
systemctl --user enable --now stay-alive-<agent_id>-social.timer
systemctl --user enable --now stay-alive-<agent_id>-community.timer
systemctl --user enable --now stay-alive-<agent_id>-reflect.timer
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
Enable all timers:
systemctl --user enable --now stay-alive-<agent_id>-light.timer
systemctl --user enable --now stay-alive-<agent_id>-social.timer
systemctl --user enable --now stay-alive-<agent_id>-community.timer
systemctl --user enable --now stay-alive-<agent_id>-reflect.timer
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
Enable all timers:
systemctl --user enable --now stay-alive-<agent_id>-light.timer
systemctl --user enable --now stay-alive-<agent_id>-social.timer
systemctl --user enable --now stay-alive-<agent_id>-community.timer
systemctl --user enable --now stay-alive-<agent_id>-reflect.timer
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
Enable all timers:
systemctl --user enable --now stay-alive-<agent_id>-light.timer
systemctl --user enable --now stay-alive-<agent_id>-social.timer
systemctl --user enable --now stay-alive-<agent_id>-community.timer
systemctl --user enable --now stay-alive-<agent_id>-reflect.timer
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
Enable all timers:
systemctl --user enable --now stay-alive-<agent_id>-light.timer
systemctl --user enable --now stay-alive-<agent_id>-social.timer
systemctl --user enable --now stay-alive-<agent_id>-community.timer
systemctl --user enable --now stay-alive-<agent_id>-reflect.timer
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
Enable all timers:
systemctl --user enable --now stay-alive-<agent_id>-light.timer
systemctl --user enable --now stay-alive-<agent_id>-social.timer
systemctl --user enable --now stay-alive-<agent_id>-community.timer
systemctl --user enable --now stay-alive-<agent_id>-reflect.timer
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
Enable all timers:
systemctl --user enable --now stay-alive-<agent_id>-light.timer
systemctl --user enable --now stay-alive-<agent_id>-social.timer
systemctl --user enable --now stay-alive-<agent_id>-community.timer
systemctl --user enable --now stay-alive-<agent_id>-reflect.timer
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
- Agent-specific BotLand auth is configured and identity probe matches.
- Dry-run cycles produce healthy local artifacts.
- Live `preflight --require-botland-live` passes.
- systemd units installed and reviewed.
- `systemd-unit-verify --require-installed` passes.
- timers enabled.
- `systemd-runtime-verify --require-installed` passes.
No suspicious patterns detected.