T02 · Agent Memory Poisoning
- Location
SKILL.md:14- Finding
Untrusted ArXiv Content Is Automatically Written to Persistent Agent Memory
- Content
View full analysis
"` to get the XML results. 2. Parse the XML (look for ``, ``, `<summary>`, and `<link title="pdf">`). 3. Present the findings to the user. 4. **MANDATORY**: Append the title, authors, date, and summary of any paper discussed to `memory/RESEARCH_LOG.md`. Use the format: ```markdown ### [YYYY-MM-DD] TITLE_OF_PAPER - **Authors**: Author List - **Link**: ArXiv Link - **Summary**: Brief summary of the paper and its relevance. ``` ``` ### Technical Analysis The Skill retrieves paper metadata and abstracts from ArXiv and can retrieve additional PDF content through `web_fetch`. Titles, author names, abstracts, and PDF text are externally supplied and therefore cannot be assumed to be trusted. The workflow mandates that information derived from every discussed paper be appended to `memory/RESEARCH_LOG.md`. It does not require user confirmation, sanitize instruction-like text, enforce a strict data-only serialization format, or mark stored content as untrusted. Consequently, a malicious ArXiv submission could include text designed to influence an Agent. If the resulting title, author data, or summary preserves that content and the memory file is later loaded as trusted context, the content can persistently affect subsequent sessions. This is an Agent memory-poisoning risk rather than direct local code execution. Exploitation depends on a later component loading the research log into Agent context and failing to maintain a trust boundary between store ...[truncated 1562 chars]- Remediation
View remediation
