T02 · Agent Memory Poisoning
- Location
SKILL.md:16- Finding
Untrusted Conversation Content Can Poison Persistent Agent Instructions
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is not overtly malicious, but it saves conversation and error details into persistent agent memory and can promote them into future instructions with broad optional hooks.
Install only if you are comfortable with the agent keeping durable notes about errors, corrections, and feature requests. Before enabling hooks or promotion, require manual review, redact secrets and private context, prefer project-scoped .learnings files, avoid automatic promotion into agent instruction files, and verify any referenced hook scripts from the installed package.
SKILL.md:16Untrusted Conversation Content Can Poison Persistent Agent Instructions
SKILL.md:35Unpinned Third-Party Installation Can Introduce Executable Hook Scripts
Creating persistent learning files under a user workspace establishes session-to-session storage for conversation-derived data. In the context of this skill, that persistence is the core mechanism, but it also means sensitive data or injected instructions can survive beyond the current task and influence future sessions.
└── FEATURE_REQUESTS.md
### Create Learning Files
```bash
mkdir -p ~/.openclaw/workspace/.learnings
These instructions explicitly encourage promoting learnings into long-lived memory and agent instruction files, which can propagate user-provided or task-derived content across future sessions. Without sanitization, this creates a durable data-retention channel for sensitive information and can also amplify prompt-injection content into trusted memory locations.
The error logging format directs the agent to store raw error messages, inputs, parameters, and environment details. Error output frequently contains secrets, tokens, file paths, proprietary code fragments, or personal data, so preserving it verbatim in markdown creates a clear confidentiality risk.
The hook example uses an empty matcher, which will fire on every user prompt and can cause pervasive prompt injection of the skill's behavior. In this skill, that increases the chance of indiscriminate logging and repeated propagation of sensitive or user-provided content into persistent files, even when the task does not warrant it.
The second hook configuration repeats the same broad activation pattern, invoking the skill for all user prompts. Combined with PostToolUse automation, this can create a high-frequency pipeline that captures conversation and tool context broadly, expanding privacy and persistence risk.
The feature-request template asks to retain user context and requested capability, which can preserve unnecessary details about user goals, internal projects, or other sensitive context. While less acute than raw error logging, it still increases retention of potentially private information without clear minimization safeguards.
No suspicious patterns detected.