T02 · Agent Memory Poisoning
- Location
SKILL.md:46- Finding
Persistent Memory Poisoning Through Mandatory Storage and Recall
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This memory skill is purpose-aligned, but it can broadly auto-activate, persist detailed user data, and run unaudited local scripts from the user's home directory.
Install only if you intend to use a persistent local memory system and trust the separate ~/.local/share/忆时 scripts and data store. Before use, narrow activation to explicit commands, require confirmation before storing personal or sensitive details, verify the helper scripts' origin and integrity, and keep controls for review, deletion, and purging of stored records.
SKILL.md:46Persistent Memory Poisoning Through Mandatory Storage and Recall
SKILL.md:44Global Agent Behavior Hijacking Through Mandatory Skill Rules
SKILL.md:19Execution of Unverified Scripts Outside the Audited Skill Package
The description embeds broad trigger phrases such as '记忆', '记住', '回想', 'recall', and 'remember', which are common in ordinary conversation and can cause the skill to activate unintentionally. In this skill, accidental activation is more dangerous than usual because the skill is explicitly designed to retrieve and persist memory, potentially causing unintended access to stored user data or unexpected writes.
The skill is explicitly built for session persistence and is granted Write and Bash capabilities while directing data storage into a local shared directory. Persistence itself may be intentional, but from a security perspective it expands the blast radius of accidental activation or over-collection because user data can be durably written and later retrieved across sessions.
description: "忆时记忆系统 - 类人记忆检索/存储/遗忘/胶囊/可视化。让 AI 拥有会遗忘、会联想、会涌现、会封存的记忆。触发词:忆时、记忆、记住、回想、回忆、recall、remember、时间胶囊、记忆检索、可视化、记忆脑图、人物画像。"
allowed-tools:
- Read
- Write
- Bash
- Glob
- Grep
The manifest trigger field contains ambiguous activation phrases without boundaries or opt-in semantics, including common words like '回忆', 'remember', and '记住'. Because this skill has read/write/bash-backed persistence features, ambiguous invocation can lead to unrequested memory retrieval, storage, or related filesystem actions from normal user phrasing.
The skill instructs the agent to proactively store 'valuable information' across broad categories like decisions, preferences, emotions, time, and context. This creates a strong natural-language privacy risk because sensitive user data may be retained persistently without granular consent, minimization, or category-based exclusions.
The requirement that stored memory be 'self-sufficient' and 'uncompressed' encourages verbatim preservation of detailed context, causes, actions, and consequences. In a memory system, that materially increases the chance of storing secrets, health details, personal identifiers, or confidential conversation fragments in durable form.
The language-style section mandates a default response style in Chinese (“默认简约直给...自动恢复正常句式”) and does not indicate that users may select another language or locale. This can violate language/locale policy expectations when no user opt-in or configurable language preference is provided.
No suspicious patterns detected.