T02 · Agent Memory Poisoning
- Location
truthlightecho.py:287- Finding
Automatic Persistence of Attacker-Controlled Filenames into Agent Memory
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mainly generates local audio, but it also performs automatic memory persistence and loads local integration modules in ways users should review before installing.
Review before installing. Use an isolated folder and virtual environment, pin dependencies, inspect any local resonance_engine.py or lyra_brain.py before running, and remove or disable the 3-Brain growth block unless you intentionally want generated run summaries stored in persistent agent memory. Avoid daemon, queue, catalog, or publishing workflows unless you explicitly intend those side effects.
truthlightecho.py:287Automatic Persistence of Attacker-Controlled Filenames into Agent Memory
truthlightecho.py:289Arbitrary Code Execution Through Working-Directory Module Hijacking
SKILL.md:96Unpinned Third-Party Package Installation and Publishing Commands
truthlightecho.py:183Unbounded Duration Permits Excessive Memory and CPU Consumption
The declared purpose is audio generation, but the skill text also advertises persistent memory growth, agent task queuing, catalog updates, and interaction with external/local subsystems like 3-Brain, Ollama Army, and publishing workflows. This mismatch is dangerous because users or agents may grant trust based on the benign creative description while the skill encourages broader state-changing behavior outside that scope.
Referenced artifact was not completely inspected
3. Copy the contents of this skill (`truthlightecho.py`, `SKILL.md`, etc.) into it. If you have lygo-resonance (and #1/#2), symlink or copy their scripts/profil
Suspicious Unicode normalization or mixed-script content
The skill describes reading inputs and producing output files, but it does not declare a permission or allowed-tools scope limiting file access. In an agent ecosystem, undeclared file_read/file_write capabilities can cause the skill to be invoked with broader filesystem access than users expect, increasing the risk of unauthorized reads, overwrites, or data leakage.
The skill description is broad and reusable across many creative, agent, and memory workflows without clear invocation boundaries. In agent systems, vague applicability increases the chance of accidental or overbroad activation, which can trigger file operations or downstream integrations in contexts the user did not intend.
The workflow examples use open-ended natural language such as growing results to memory, assigning army roles, and layering outputs, without constraints or confirmation points. In an autonomous or semi-autonomous agent environment, these broad instructions can be interpreted as authorization to perform multi-step state-changing actions beyond simple audio synthesis.
The daemon and queue-based role references encourage background or batch operation but do not specify trigger conditions, approval requirements, rate limits, or scope boundaries. That ambiguity can lead to uncontrolled processing, unintended persistence, or unexpected agent activity if integrated into an orchestration framework.
The publish instruction uses 'npx clawhub@latest', which pulls and executes the latest remote package version at runtime. This creates a supply-chain risk: if the upstream package is compromised or changed unexpectedly, users may run attacker-controlled code during publishing or maintenance workflows.
The code unconditionally attempts to persist a generated summary into an external '3-Brain' memory system that is outside the tool's stated purpose of producing local audio and JSON outputs. This creates undisclosed data retention and secondary data flow risk, especially because user-supplied filenames and derived metadata are included in the persisted summary.
The LyraThreeBrainMemory integration is not necessary for harmonic echo generation and represents hidden functionality that expands the skill's behavior into persistence and possible cross-tool data sharing. Even if local, such undocumented side effects can leak sensitive project names, input filenames, or workflow context into a longer-lived memory store.
The code performs an additional persistent write to a memory subsystem without explicit disclosure or consent, unlike the expected WAV/JSON outputs. This is more dangerous than ordinary file output because it stores derived user context in a secondary repository that may be reused, indexed, or exposed by other components.
The module docstring states the skill outputs a stereo WAV, JSON profile, and optional stems and MIDI. In the implementation, the only output files produced are the WAV at L227/L269 and the JSON profile at L283-L284; there is no code path generating stems or MIDI, so the documentation overstates actual behavior.
The script writes a WAV file at L227 and a JSON profile at L283-L284. Although outputs are implied by the module docstring and printed after completion, the code does not provide a user-facing warning or confirmation before creating these files, which is the kind of file-write disclosure this rule asks for in code files.
No suspicious patterns detected.