T02 · Agent Memory Poisoning
- Location
SKILL.md:176- Finding
Untrusted Remote KOL Data Is Directed into Persistent Agent Memory
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 176–188
Vulnerability Type: Persistent storage of externally supplied content
Risk Level: MediumVulnerable Documentation Excerpt
The following is an English translation of the relevant instruction and its associated request:
text ### 17. Learn a KOL Strategy (Core API) Retrieve a KOL's complete strategy knowledge package in one request, including the strategy profile, statistics by asset and direction, and historical trades with technical indicators at entry. After calling this API, the data should be stored in the agent's own memory so that subsequent trading questions can be answered using the strategy. curl -s -X POST "https://server.tokenbeep.com/mcp/" \ -H "Content-Type: application/json" \ -H "Accept: application/json, text/event-stream" \ -H "Authorization: Bearer $CUTIE_API_KEY" \ -d '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"cutie_learn_from_kol","arguments":{"kol_id":"KOL_ID","include_trades":30}}}' \ | jq '.result.content[0].text | fromjson'Technical Analysis
The Skill explicitly instructs the agent to place data returned by the remote
cutie_learn_from_kolMCP tool into its own memory. The response includes KOL-generated or server-generated strategy summaries, profiles, and historical trade data. This content crosses an external trust boundary and is not inherently trustworthy.No safeguards are specified before persistence:
- No strict response-schema validation is required.
- No filtering or neutralization of instruction-like text is required.
- No separation is established between factual application data and agent instructions.
- No source or provenance metadata is required in the stored record.
- No user confirmation is required before persistent storage.
- No retention period, scope restriction, or deletion mechanism is described.
- No instruction requires the agent to treat retrieved text exclusively as untrusted d ...[truncated 2420 chars]
- Remediation
View remediation
Remediation Suggestions
-
Remove the instruction to persist raw responses. Do not direct the agent to store the complete MCP response in behavioral or general-purpose long-term memory.
-
Use isolated structured storage. If strategy retention is required, store only validated factual fields in a dedicated application record scoped to the current user and KOL. Do not store remote text as agent instructions or preferences.
-
Apply a strict allowlist schema. Accept only documented fields with enforced types, lengths, ranges, and enumerated values. Reject unknown properties and unexpectedly formatted values.
-
Neutralize instruction-like content. Treat every string returned by the remote service as untrusted data. Strip or quarantine text that attempts to direct agent behavior, override policies, invoke tools, request secrets, or alter future responses.
-
Preserve provenance. Record the source endpoint, KOL identifier, retrieval time, schema version, and expiration time. Clearly label retained content as untrusted third-party financial data.
-
Require explicit user consent. Ask the user before saving strategy data beyond the current interaction and explain what will be stored, why it is needed, and how it can be deleted.
-
Set retention and deletion controls. Apply a short expiration period and provide a way to inspect, refresh, and delete saved KOL strategy records.
-
Limit retrieval effects. When using saved records, provide them only as quoted reference data and explicitly prohibit their contents from changing system instructions, safety controls, tool permissions, or unrelated behavior.
-
Isolate memory scope. Prevent records from crossing user, tenant, workspace, or unrelated conversation boundaries.
-
Add integrity and anomaly checks. Reject oversized responses, unexpected markup, prompt-like directives, embedded URLs where not expected, and material changes inconsistent with the documented response mo ...[truncated 375 chars]
-
