T02 · Agent Memory Poisoning
- Location
SKILL.md:271- Finding
Persistent Prompt Injection Through Self-Modification of Skill Instructions
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 271–272 and 293–294
Vulnerability Type: Persistent agent memory poisoning through modification of executable skill instructions
Risk Level: HighVulnerable Code Snippets:
markdown **Add custom topics:** - Edit the SKILL.md and add new topics to the "Core Topics" section - "Add [topic] to the skill"markdown ### Contributing Extensions When you extend the skill: 1. Edit `~/.openclaw/workspace/skills/learning-forge/SKILL.md` 2. Add your custom content to the appropriate sectionTechnical Analysis
SKILL.mdis not merely passive user data; its contents become instruction context when the skill is loaded. The quoted instructions explicitly permit user-requested content to be written into this file.No trust boundary, content schema, validation rule, safe section, review requirement, or restriction against behavioral directives is defined. Consequently, an attacker can present malicious agent instructions as a custom topic or extension. If those instructions are inserted into
SKILL.md, they may be interpreted as trusted skill instructions in subsequent sessions.This differs from ordinary note storage because the destination controls agent behavior. The resulting prompt injection persists beyond the original interaction and can continue to influence future sessions whenever the modified skill is loaded.
Attack Path
- An attacker asks the agent to add a custom topic or extension to the skill.
- The submitted content includes concealed behavioral directives, such as instructions to disregard future user constraints, expose available context, or perform unrelated tool operations.
- Following lines 271–272 or 293–294, the agent writes that attacker-controlled content into the installed
SKILL.md. - OpenClaw loads the modified skill during a later session.
- The injected content is interpreted as part of the ...[truncated 957 chars]
- Remediation
View remediation
Remediation Suggestions
- Do not write user-controlled content directly into
SKILL.mdor any other file loaded as agent instructions. - Keep the installed skill definition immutable during normal operation.
- Store custom topics and extensions as inert data in a separate file with a strict schema, such as JSON containing only fields like
title,description, andresources. - Validate field lengths and allowed types, and reject content containing role directives, tool instructions, instruction-priority language, or attempts to alter security controls.
- Render stored extensions as quoted or otherwise clearly delimited untrusted data rather than executable instruction context.
- Require explicit user confirmation and display a complete diff before any modification to skill configuration.
- Restrict writes to approved data directories and use least-privilege filesystem permissions.
- Maintain a trusted baseline, integrity hash, version history, and rollback mechanism for the original
SKILL.md. - If extension code or behavioral instructions are genuinely required, place them through a separate reviewed installation process rather than a conversational self-editing workflow.
- Do not write user-controlled content directly into
