T02 · Agent Memory Poisoning
- Location
criteria.md:5- Finding
Persistent Preference Writes Can Bypass Explicit User Confirmation
- Content
View full analysis
Vulnerability Details
File Location:
criteria.md:5-15; related persistent loading behavior atSKILL.md:56-65, 85-88
Vulnerability Type: Persistent memory poisoning through contradictory confirmation requirements
Risk Level: MediumVulnerable code snippets:
criteria.md:5-15markdown ## When to Add **Immediate (1 occurrence):** - User explicitly says "always use X" or "never do Y" - User corrects your choice → add their preference - User rejects a suggestion → add to Never **After repeated explicit feedback (2+ times):** - User explicitly accepted your choice twice - User stated same preference in multiple conversations - User explicitly approved your approach multiple timesSKILL.md:56-65markdown ### 1. Learn from Explicit Feedback Only - User corrects output → ask: "Should I remember this preference?" - User confirms → add to `~/coding/memory.md` - Never infer from silence or observation ### 2. Confirmation Required No preference is stored without explicit user confirmation: - "Actually, I prefer X" → "Should I remember: prefer X?" - User says yes → store - User says no → don't store, don't ask againSKILL.md:85-88markdown ### 6. On Session Start 1. Load `~/coding/memory.md` if exists 2. Apply stored preferences to responses 3. If no file exists, start with no assumptionsTechnical Analysis
SKILL.mdrequires explicit confirmation before a preference is written to persistent storage. However, the referencedcriteria.mdfile instructs the agent to add preferences immediately when a user corrects an answer or rejects a suggestion. It also permits storage after repeated acceptance without requiring a dedicated confirmation to persist the information.Because
SKILL.md:30identifiescriteria.mdas the authoritative reference for deciding when to add preferences, an agent may follow the less restrictive criteria and write ...[truncated 1746 chars]- Remediation
View remediation
Remediation Suggestions
- Change every persistence condition in
criteria.mdto require an explicit, immediate confirmation before writing:markdown - User corrects your choice → ask whether to remember it - User rejects a suggestion → ask whether to add it to Never - Repeated approval → ask whether to store it as a general preference - Add an explicit precedence rule stating that
SKILL.mdconfirmation requirements override all supporting documents. - Distinguish between applying feedback to the current response and persisting it for future sessions.
- Require the agent to show the exact normalized entry and target file before obtaining confirmation.
- Reject project-specific requirements, secrets, executable instructions, commands, and safety-policy changes from persistent preference storage.
- Record provenance and confirmation status for each entry, or maintain a minimal audit log recording when the user approved it.
- Add tests covering corrections, rejected suggestions, repeated approval, ambiguous responses, and explicit refusal to ensure none causes an unauthorized write.
- Change every persistence condition in
