T02 · Agent Memory Poisoning
- Location
SKILL.md:526- Finding
Persistent Agent Memory Modification Outside the Prototype Task Scope
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This prototype-design skill is mostly coherent, but it normalizes broad repository commits, persistent memory files, unpinned command execution, and an active HTML reference file that users should review before installing.
Review this skill before installing. It can be useful for HTML prototype work, but do not let it run broad `git add -A` commits, write memory files, or start an unpinned `npx` server unless you explicitly want those side effects. Consider removing or sanitizing the captured `linear.app-DESIGN.md` HTML reference before use.
SKILL.md:526Persistent Agent Memory Modification Outside the Prototype Task Scope
SKILL.md:722Unpinned Third-Party Package Download and Execution Through npx
SKILL.md:750Overbroad Repository Staging and Automatic Git History Modification
references/design-systems/linear.app-DESIGN.md:1Executable Third-Party HTML Stored as a Passive Design Reference
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
<div id="page-xxx" class="page">
<!-- 1. Header -->
<header class="header">
<div class="header-left">
<h2>页面标题</h2>
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
<!-- 外层容器 -->
<div class="ant-table-wrapper" style="display:flex;flex-direction:column;overflow:hidden;height:500px;">
<!-- 表头 - 固定不滚动 -->
<div class="ant-table-header" style="overflow:hidden;border-bottom:2px solid #E5E7EB;flex-shrink:0;">
<table style="table-layout:fixed;width:1800px;border-collapse:collapse;font-size:14px;">
<colgroup>
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
<!-- 弹窗在这里,页面关闭后的位置 -->
<div id="modal-add-org" style="display:none...">...</div>
<!-- ✅ 正确:弹窗必须在页面 div 内部 -->
<div id="page-system_org" class="page">
...页面内容...
<!-- 弹窗必须放在这里 -->
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
<!-- 弹窗在这里,页面关闭后的位置 -->
<div id="modal-add-org" style="display:none...">...</div>
<!-- ✅ 正确:弹窗必须在页面 div 内部 -->
<div id="page-system_org" class="page">
...页面内容...
<!-- 弹窗必须放在这里 -->
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
<!DOCTYPE html><html lang="en"><head><meta charSet="utf-8"/><meta name="viewport" content="width=device-width, initial-scale=1"/><link rel="preload" as="image" href="https://github.com/VoltAgent.png?size=32"/><script async="" src="https://www.googletagmanager.com/gtag/js?id=G-FFCDX6VFEW"></script><link rel="preload" href="/fonts/Geist-Variable.woff2" as="font" type="font/woff2" crossorigin="anonymous"/><link rel="preload" href="/fonts/GeistMono-Variable.woff2" as="font" type="font/woff2" crossorigin="anonymous"/><link rel="preload" href="/fonts/GeistPixel-Line.woff2" as="font" type="font/woff2" crossorigin="anonymous"/><title>Linear Inspiration Design System — DESIGN.md</title><meta name="description" content="Project management. Ultra-minimal, precise, purple accent."/><meta property="og:title" content="Linear Inspiration Design System — DESIGN.md"/><meta property="og:description" content="Project management. Ultra-minimal, precise, purple accent."/><meta property="og:type" content="article"/><meta name="twitter:card" content="summary_large_image"/><meta name="twitter:title" content="Linear Inspiration Design System — DESIGN.md"/><meta name="twitter:description" content="Project management. Ultra-minimal, precise, purple accent."/><link rel="modulepreload" href="/assets/main-DN7xrynx.js"/><link rel="modulepreload" href="/assets/_owner.design-md-CncuogEY.js"/><link rel="modulepreload" href="/assets/Footer-BlhWBFnL.js"/><link rel="modulepreload" href="/assets/Header--xjVVFQI.js"/><link rel="modulepreload" href="/assets/design-stars-BXogl9gC.js"/><link rel="icon" type="image/svg+xml" href="/favicon.svg"/><link rel="icon" type="image/png" href="/favicon-32.png" sizes="32x32"/><link rel="icon" type="image/png" href="/favicon-16.png" sizes="16x16"/><link rel="apple-touch-icon" href="/apple-touch-icon.png" sizes="180x180"/><link rel="manifest" href="/site.webmanifest"/><link rel="stylesheet" href="/assets/styles-CsA7WhNu.css"/><script>window.dataLayer = window.dataLayer |
...[truncated 27 chars]
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
<!DOCTYPE html><html lang="en"><head><meta charSet="utf-8"/><meta name="viewport" content="width=device-width, initial-scale=1"/><link rel="preload" as="image" href="https://github.com/VoltAgent.png?size=32"/><script async="" src="https://www.googletagmanager.com/gtag/js?id=G-FFCDX6VFEW"></script><link rel="preload" href="/fonts/Geist-Variable.woff2" as="font" type="font/woff2" crossorigin="anonymous"/><link rel="preload" href="/fonts/GeistMono-Variable.woff2" as="font" type="font/woff2" crossorigin="anonymous"/><link rel="preload" href="/fonts/GeistPixel-Line.woff2" as="font" type="font/woff2" crossorigin="anonymous"/><title>Linear Inspiration Design System — DESIGN.md</title><meta name="description" content="Project management. Ultra-minimal, precise, purple accent."/><meta property="og:title" content="Linear Inspiration Design System — DESIGN.md"/><meta property="og:description" content="Project management. Ultra-minimal, precise, purple accent."/><meta property="og:type" content="article"/><meta name="twitter:card" content="summary_large_image"/><meta name="twitter:title" content="Linear Inspiration Design System — DESIGN.md"/><meta name="twitter:description" content="Project management. Ultra-minimal, precise, purple accent."/><link rel="modulepreload" href="/assets/main-DN7xrynx.js"/><link rel="modulepreload" href="/assets/_owner.design-md-CncuogEY.js"/><link rel="modulepreload" href="/assets/Footer-BlhWBFnL.js"/><link rel="modulepreload" href="/assets/Header--xjVVFQI.js"/><link rel="modulepreload" href="/assets/design-stars-BXogl9gC.js"/><link rel="icon" type="image/svg+xml" href="/favicon.svg"/><link rel="icon" type="image/png" href="/favicon-32.png" sizes="32x32"/><link rel="icon" type="image/png" href="/favicon-16.png" sizes="16x16"/><link rel="apple-touch-icon" href="/apple-touch-icon.png" sizes="180x180"/><link rel="manifest" href="/site.webmanifest"/><link rel="stylesheet" href="/assets/styles-CsA7WhNu.css"/><script>window.dataLayer = window.dataLayer |
...[truncated 27 chars]
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
<!DOCTYPE html><html lang="en"><head><meta charSet="utf-8"/><meta name="viewport" content="width=device-width, initial-scale=1"/><link rel="preload" as="image" href="https://github.com/VoltAgent.png?size=32"/><script async="" src="https://www.googletagmanager.com/gtag/js?id=G-FFCDX6VFEW"></script><link rel="preload" href="/fonts/Geist-Variable.woff2" as="font" type="font/woff2" crossorigin="anonymous"/><link rel="preload" href="/fonts/GeistMono-Variable.woff2" as="font" type="font/woff2" crossorigin="anonymous"/><link rel="preload" href="/fonts/GeistPixel-Line.woff2" as="font" type="font/woff2" crossorigin="anonymous"/><title>Linear Inspiration Design System — DESIGN.md</title><meta name="description" content="Project management. Ultra-minimal, precise, purple accent."/><meta property="og:title" content="Linear Inspiration Design System — DESIGN.md"/><meta property="og:description" content="Project management. Ultra-minimal, precise, purple accent."/><meta property="og:type" content="article"/><meta name="twitter:card" content="summary_large_image"/><meta name="twitter:title" content="Linear Inspiration Design System — DESIGN.md"/><meta name="twitter:description" content="Project management. Ultra-minimal, precise, purple accent."/><link rel="modulepreload" href="/assets/main-DN7xrynx.js"/><link rel="modulepreload" href="/assets/_owner.design-md-CncuogEY.js"/><link rel="modulepreload" href="/assets/Footer-BlhWBFnL.js"/><link rel="modulepreload" href="/assets/Header--xjVVFQI.js"/><link rel="modulepreload" href="/assets/design-stars-BXogl9gC.js"/><link rel="icon" type="image/svg+xml" href="/favicon.svg"/><link rel="icon" type="image/png" href="/favicon-32.png" sizes="32x32"/><link rel="icon" type="image/png" href="/favicon-16.png" sizes="16x16"/><link rel="apple-touch-icon" href="/apple-touch-icon.png" sizes="180x180"/><link rel="manifest" href="/site.webmanifest"/><link rel="stylesheet" href="/assets/styles-CsA7WhNu.css"/><script>window.dataLayer = window.dataLayer |
...[truncated 27 chars]
The file contains embedded NUL bytes inside serialized route/state data, which can confuse downstream parsers, truncation-prone tooling, or security scanners that expect plain text DESIGN.md content. In an agent skill context, malformed control characters increase prompt/parsing ambiguity and can be leveraged to hide instructions or bypass validation logic.
The title explicitly presents the skill as a Chinese-language skill ("通用页面原型设计技能"), and the README is entirely written in Chinese with no indication that other languages are supported. This can violate language/locale policy when a skill constrains interaction language without user opt-in or documented justification.
The manifest description and usage guidance are written entirely in Chinese and present the skill as a general-purpose prototype design skill, not a China-specific or Chinese-only tool. That creates a natural-language locale constraint without user opt-in or a documented justification.
The markdown includes synchronization and rebuild scripts that write back to index.html and advises repeated modification of files in pages/ and memory/. Although the steps are operationally clear, the skill description does not warn that these commands will overwrite local project files and may replace existing content.
The skill directs the agent to write persistent conversation state into memory/YYYY-MM-DD.md, which is outside the stated prototype-design scope. Persisting summaries can leak user data, retain sensitive context unnecessarily, and create hidden state that influences future tasks without the user's informed consent.
The skill instructs the agent to perform git add and git commit as part of its normal workflow, even though version-control mutation is not necessary to design HTML prototypes. This expands the skill's authority from content generation into persistent repository modification, which can create unwanted history changes, commit sensitive files, or make destructive actions appear routine.
The skill includes instructions to start a local HTTP server and drive a browser automation tool, which goes beyond basic prototype authoring into active environment control. That broadens the attack surface by normalizing command execution and automated interaction with local services, potentially causing unintended network exposure or side effects in the user's environment.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
The embedded HTML loads Google Analytics (gtag.js) and initializes tracking without any visible disclosure or consent notice in the content. In a reusable skill/reference file, this introduces silent third-party telemetry and unexpected data flows if the content is rendered in a browser-like environment.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
Line L055 specifies fallback fonts "with CJK: Noto Sans KR/SC/JP," which encodes a specific locale/language handling choice in natural-language guidance. The file does not offer user opt-in, broader locale options, or a justification that this is a region-specific tool, so this can conflict with organizational language/locale choice policies.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
- Don't apply border-radius between 13px and 99998px -- the system jumps from 12px (large card) directly to pill (99999px)
- Don't mix the coral-red CTA with the electric blue interactive color in the same element
- Don't use heavy font weights (700+) -- the system maxes out at 600 and only for 11px uppercase labels
- Don't place light text on light surfaces or dark text on dark surfaces without checking the gray-on-gray contrast ratio
- Don't use traditional offset box-shadows -- ring shadows (0 0 0 Npx) or border-based containment only
- Don't break the tight line-height on headings -- 1.00-1.24 is the range, never go to 1.5+ for display text
This markdown file contains prescriptive language such as 'the monochromatic palette is sacred' and 'don't use colored status indicators unless absolutely necessary,' which constrains output to one visual/locale-style convention without offering user opt-in or exceptions. Because the rule covers natural-language policy violations across all file types, this is a policy concern where the skill language can force a single presentation choice rather than allowing user needs to override it.
The file documents operations such as resetting passwords, forcing users offline, unfreezing accounts, and disabling/enabling access, but does not include any warning that these are security-sensitive or potentially disruptive actions. For markdown files, SQP-2 applies when behavior affecting user accounts or system integrity is described without cautionary language.
The guidance recommends both Git commits and updates to memory files without prominently warning that persistent local state and repository history will be changed. In context, this matters because the skill already exceeds its design remit by encouraging persistent side effects beyond prototype creation.
The 'common mistakes' section says not to use CSS class names such as class="modal" or class="btn btn-primary" and to rely entirely on inline styles for modal components. Later sections define and recommend shared class names like .page, .header, .btn, and .btn-primary, creating contradictory implementation guidance within the skill documentation.
The documented rule says the content box must not use overflow:hidden and instead must use overflow-y:auto. However, the immediately preceding modal template sets the outer content box to overflow:hidden at L0160 while placing scroll behavior on an inner content area, so the prose instruction and example actively conflict.
The document prescribes BMWTypeNextLatin and a fallback stack that explicitly includes Japanese fonts, presenting the design guidance as universal rather than optional or context-specific. Because the file does not offer a user language/locale choice or explain when these locale-specific font selections should apply, it can be read as forcing a locale-associated presentation policy.
No suspicious patterns detected.