T02 · Agent Memory Poisoning
- Location
inventory.py:78- Finding
Stored Prompt Injection Through Unescaped Skill Metadata
- Content
View full analysis
list: """从 SKILL.md 中提取触发词""" skill_file = skill_dir / "SKILL.md" if not skill_file.exists(): return [] triggers = [] content = skill_file.read_text(encoding='utf-8') # 查找触发词列表(简化版:匹配常见的触发词模式) lines = content.split('\n') for i, line in enumerate(lines): # 匹配触发词表格或列表 if '触发词' in line or 'trigger' in line.lower(): # 读取接下来的几行 for j in range(i+1, min(i+10, len(lines))): next_line = lines[j].strip() if next_line and not next_line.startswith('#'): # 提取引号中的内容 matches = re.findall(r'["「]([^"」]+)["」]', next_line) triggers.extend(matches) if next_line.startswith('#') or next_line.startswith('---'): break return triggers[:5] # 最多5个 ``` Untrusted descriptions are extracted without validation or Markdown escaping: ```python content = skill_file.read_text(encoding='utf-8') lines = content.split('\n') # 查找描述(第一段非注释内容) for line in lines: line = line.strip() if line and not line.startswith('---') and not line.startswith('#'): # 移除可能的 frontmatter if ':' in line and not line.startswith('name:'): info["description"] = line[:100] break elif line.startswith('description:'): # 多行描述 desc_lines = [] for j in lines[lines.index(line)+1:]: if j.strip().startswith('---'): break desc_lines.append(j.strip()) ...[truncated 3835 chars]- Remediation
View remediation
