T02 · Agent Memory Poisoning
- Location
scripts/memory-recovery.sh:9- Finding
Untrusted Persistent Memory Is Loaded Without Validation or Trust Boundaries
- Content
View full analysis
Vulnerability Details
File Location:
scripts/memory-recovery.sh, lines 9-39
Vulnerability Type:T02: Agent Memory Poisoning
Risk Level: MediumVulnerable Code
bash TODAY=$(date +%Y-%m-%d) if [ -f "memory/$TODAY.md" ]; then echo "--- 今日记忆 ($TODAY) ---" cat memory/$TODAY.md echo "" fi # 2. 读取永久记忆 echo "♾️ 读取永久记忆..." if [ -f "memory/permanent/identity.md" ]; then echo "--- 身份与偏好 ---" cat memory/permanent/identity.md echo "" fi if [ -f "memory/permanent/technical-stack.md" ]; then echo "--- 技术栈 ---" cat memory/permanent/technical-stack.md echo "" fi if [ -f "memory/permanent/working-directory.md" ]; then echo "--- 工作目录与习惯 ---" cat memory/permanent/working-directory.md echo "" fi if [ -f "memory/permanent/key-decisions.md" ]; then echo "--- 关键决策与教训 ---" cat memory/permanent/key-decisions.md echo "" fiTechnical Analysis
The recovery script reads persistent memory files and emits their contents directly to standard output. It does not validate file ownership, permissions, type, size, integrity, or content. It also does not distinguish recovered information from instructions that an AI agent might execute.
If the script output is supplied to an agent as restored context, content placed in these files can cross the boundary between untrusted stored data and trusted agent instructions. In particular,
identity.mdandkey-decisions.mdmay be interpreted as authoritative identity, policy, or decision context.The script does not itself write malicious content, and exploitation requires an attacker or compromised process to have write access to one of the referenced files. Nevertheless, once such access exists, the automatic recovery process provides a path for adversarial instructions to persistently influence later sessions.
Attack Path
- An attacker, compromised local process, o ...[truncated 1714 chars]
- Remediation
View remediation
Remediation Suggestions
-
Enforce filesystem access controls
- Require memory files to be owned by the expected user.
- Reject files writable by group or other users.
- Restrict the memory directory and files with permissions such as
0700and0600, where operationally appropriate.
-
Validate paths and file types
- Resolve each path to a canonical path and confirm that it remains inside the approved memory directory.
- Reject symbolic links, device files, named pipes, sockets, and other non-regular files.
- Use quoted path expansions consistently, including
cat "memory/$TODAY.md".
-
Add integrity protection
- Maintain authenticated hashes or digital signatures for trusted permanent-memory records.
- Refuse to load records whose integrity cannot be verified.
- Record provenance, modification time, and the component responsible for each update.
-
Establish an instruction-data boundary
- Mark restored memory explicitly as untrusted reference data.
- Ensure the agent is instructed not to treat commands or policy statements inside memory records as executable instructions.
- Parse a constrained schema instead of inserting arbitrary Markdown directly into the agent context.
-
Control sensitive changes
- Require explicit user approval before accepting changes to identity, security policy, tool permissions, or key decisions.
- Separate ordinary session notes from privileged identity and policy records.
-
Apply resource limits
- Set maximum file and aggregate memory sizes.
- Reject malformed, unexpectedly large, or binary content.
- Load only the fields necessary for the current task.
-
Audit memory updates
- Log all writes and modifications to persistent memory.
- Alert on unexpected changes to permanent files.
- Provide version history and a trusted rollback mechanism.
-
