T02 · Agent Memory Poisoning
- Location
SKILL.md:80- Finding
Persistent Spam-Rule Poisoning Through Unverified Email Classification
- Content
View full analysis
**Solicitor Rule**: A sender asking for a reply (e.g., "let me know if you're interested") does > NOT automatically create a WaitingReply item. If the email itself is a solicitation, it goes to > Spam regardless of how it's phrased. Move to `/Spam`. Add sender domain to spam list in state (unless it is a major legitimate service domain like gmail.com, outlook.com — add the full address instead). ``` The persistence of the resulting rule is reinforced at `SKILL.md`, line 265: ```markdown - Spam additions are **permanent** in state unless user removes them. ``` The persistent storage location is defined in `references/rules-and-state.md`, lines 29-39: ```markdown ## Spam Sender List > Individual email addresses or domains to always route to /Spam. > Never add broad domains like gmail.com or outlook.com — add specific addresses only for those. ``` # Format: address_or_domain | date_added | reason # Example: # noreply@sketchy-promo.com | 2024-01-15 | unsolicited marketing ``` ...[truncated 2455 chars]- Remediation
View remediation
