T02 · Agent Memory Poisoning
- Location
scripts/learn_lesson.py:25- Finding
Untrusted Lessons Are Persisted and Propagated Across Agent Workspaces
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is openly for agent self-improvement, but it can persist and copy lessons across all local agent workspaces without enough scoping or safeguards.
Install only if you are comfortable with local JSON records of evaluations and lessons being retained and potentially copied to other WorkBuddy agent workspaces. Avoid storing secrets, customer data, private prompts, or unreviewed instructions as lessons, and prefer running the sync step only after reviewing the shared knowledge file and confirming the intended target workspaces.
scripts/learn_lesson.py:25Untrusted Lessons Are Persisted and Propagated Across Agent Workspaces
scripts/config.py:37Ambiguous Workspace Selection Can Modify the Wrong Agent's State
The README's substantive instructions and descriptions are written in Chinese, including the introduction, usage guidance, and data descriptions. This imposes a language constraint on users without any opt-in, alternative language option, or explanation that the skill is intended only for a Chinese-speaking or region-specific context.
The README explicitly promotes cross-agent experience sharing and a shared knowledge base, but it provides no warning about privacy boundaries, sensitive data handling, or isolation between agents. In a self-improving agent context, lessons learned and evaluations can easily contain prompts, outputs, identifiers, or business context, so undocumented sharing increases the risk of unintended data exposure across agents or users.
All user-facing instructions, triggers, parameter explanations, and operational guidance are presented only in Chinese. If organizational policy requires not forcing a specific language without user opt-in, this file violates that expectation because it does not offer alternative languages or state that the skill is intentionally limited to a Chinese-speaking context.
The activation conditions are broad enough to trigger on common phrases like performance analysis or improving efficiency, which can cause the skill to activate outside narrowly intended contexts. In an agent environment, unintended activation can lead to unnecessary self-evaluation, workflow changes, or follow-on actions that affect task handling without explicit user intent.
The skill explicitly describes writing evaluation and lesson data to persistent workspace files and synchronizing learning into a shared cross-agent knowledge store, but it does not warn about retention, sensitivity, consent, or access control. This creates a real risk of storing confidential task details or propagating sensitive information across agents and sessions beyond the original task scope.
The activation conditions are broad and ambiguous, including phrases like "optimize workflow" and "Any scenario where the Agent needs to learn from mistakes," which can cause the skill to trigger in contexts far beyond explicit user intent. In an agentic system, overly broad activation can lead to unintended evaluation, logging, and downstream file-writing behavior, increasing the chance of unauthorized persistence or modification of workspace state.
The skill explicitly documents writing evaluation records, lessons learned, optimization plans, and shared collective knowledge into workspace and shared-context locations, but does not warn that activating the skill will persist data or affect shared state. This is dangerous because an agent may create or alter local and cross-agent files without the user's awareness, potentially causing data leakage, contamination of shared knowledge, or unintended retention of sensitive task details.
This Python file contains natural-language documentation and CLI help text in Chinese, including the module docstring and argument descriptions, without indicating any user language selection or regional constraint. That can violate a language/locale policy when a skill implicitly forces one language for interaction or understanding.
The module docstring and function docstring are written in Chinese, and the CLI parser description also uses Chinese, which imposes a language choice on users without opt-in. This matches the language/locale policy concern because the script does not offer an alternative language or document a justified locale restriction.
The argparse description and help text are presented only in Chinese for a general-purpose optimization script. Because no language selection or documented locale constraint is provided, this is a natural-language policy violation under the language/locale rule.
The file's natural-language description includes Chinese-only wording ("跨 Agent 同步学习成果") and the function/CLI descriptions are also written in Chinese, with no indication that users may choose another language. Under the stated policy, forcing or assuming a specific language without opt-in is a natural-language policy violation.
The line "Record tool usage注意事项" mixes English with Chinese in a file named SKILL_en.md, which implies an English-language skill. This can violate language consistency expectations because the file does not offer a user language choice or explain the multilingual requirement.
This code file contains user- or maintainer-facing natural language in Chinese (for example the module docstring at L04), which can impose a language expectation without any opt-in or documented locale constraint. Under the policy, forcing a specific language without user choice is a natural-language policy concern.
This code contains user-facing natural-language text in both Chinese and English, including the module docstring, argparse help strings, and console output. Because it imposes mixed locale behavior without any explicit user opt-in or language selection, it can violate the policy against forcing a specific language or locale.
No suspicious patterns detected.