T02 · Agent Memory Poisoning
- Location
SKILL.md:293- Finding
Unreviewed Learnings Can Be Promoted into Persistent Agent Instructions
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:293-320
Vulnerability Type: Persistent agent memory and instruction poisoning
Risk Level: HighVulnerable Code
markdown ## Promoting to Project Memory When a learning is broadly applicable (not a one-off fix), promote it to permanent project memory. ### When to Promote - Learning applies across multiple files/features - Knowledge any contributor (human or AI) should know - Prevents recurring mistakes - Documents project-specific conventions ### Promotion Targets | Target | What Belongs There | |--------|-------------------| | `CLAUDE.md` | Project facts, conventions, gotchas for all Claude interactions | | `AGENTS.md` | Agent-specific workflows, tool usage patterns, automation rules | | `.github/copilot-instructions.md` | Project context and conventions for GitHub Copilot | | `SOUL.md` | Behavioral guidelines, communication style, principles (OpenClaw workspace) | | `TOOLS.md` | Tool capabilities, usage patterns, integration gotchas (OpenClaw workspace) | ### How to Promote 1. **Distill** the learning into a concise rule or fact 2. **Add** to appropriate section in target file (create file if needed) 3. **Update** original entry: - Change `**Status**: pending` → `**Status**: promoted` - Add `**Promoted**: CLAUDE.md`, `AGENTS.md`, or `.github/copilot-instructions.md`Additional reinforcement appears in
SKILL.md:377-391, where recurring patterns are promoted into agent context or system-prompt files, and inSKILL.md:499, which states:markdown 7. **Promote aggressively** - if in doubt, add to CLAUDE.md or .github/copilot-instructions.mdThe optional bootstrap hook also reinforces promotion into persistent instruction files in
hooks/openclaw/handler.js:30-33:javascript **Promote when pattern is proven:** - Behavioral patterns → \`SOUL.md\` - Workflow improvements → \`AGENTS.md\` - Too ...[truncated 2596 chars]- Remediation
View remediation
Remediation Suggestions
- Require explicit user confirmation before every write to an agent instruction or persistent-context file.
- Present the exact destination, proposed text, and unified diff before requesting approval.
- Never promote content copied directly from command output, repository documents, external APIs, issue text, or transcripts.
- Track provenance and trust level for every learning. Permit promotion only from trusted, user-verified sources.
- Store ordinary learnings in a dedicated data-only file that is not interpreted as agent instructions.
- Treat
CLAUDE.md,AGENTS.md,.github/copilot-instructions.md,SOUL.md, andTOOLS.mdas security-sensitive configuration. - Add validation that rejects instructions involving credential access, safety-constraint changes, hidden execution, unapproved network access, or privilege expansion.
- Replace “promote aggressively” with a default-deny policy requiring deliberate review.
- Record an immutable audit entry containing the approval event, source learning, exact diff, timestamp, and destination.
- Provide a rollback mechanism for every promoted rule.
