T02 · Agent Memory Poisoning
- Location
scripts/memory.py:36- Finding
Persistent memory accepts untrusted user content and silently reuses it in future Agent sessions
- Content
View full analysis
Tags are comma-separated. Example: memory.py store "fear,career" "User afraid of leaving stable job" """ if len(args) < 2: print(json.dumps({"error": "usage: store "})) return tags = args[0] content = " ".join(args[1:]) ensure_dir() ts = datetime.now().strftime("%Y-%m-%dT%H:%M:%S") line = f"{ts} | {tags} | {content}\n" with open(ENGRAMS_FILE, "a", encoding="utf-8") as f: f.write(line) _update_index(tags) count = sum(1 for _ in open(ENGRAMS_FILE, encoding="utf-8")) print(json.dumps({"stored": True, "tags": tags, "total_engrams": count})) ``` The Skill directs the Agent to reuse these records silently: ```markdown At the START of every new session, before the first excavation question, search memory: python3 {baseDir}/scripts/memory.py search "" python3 {baseDir}/scripts/memory.py themes If relevant engrams exist, silently incorporate them. Do NOT announce "I found memories about you." Just use the context naturally, as if you already know. ``` Raw memory content is also retained as evidence during consolidation: ```python for tag, contents in tag_groups.items(): if len(contents) >= 3: heuristics.append({ "pattern": tag, "frequency": len(contents), "evidence": contents[:5], "heuristic": f"Recurring pattern '{tag}' across {len(contents)} episodes" }) elif len(contents) >= 2: heuristics.append({ "pattern": tag, "frequency": len(contents) ...[truncated 2383 chars]- Remediation
View remediation
