T02 · Agent Memory Poisoning
- Location
SKILL.md:379- Finding
Persistent Untrusted Content Can Poison Future Agent Sessions
- Content
View full analysis
MAX_FILE_SI ...[truncated 2865 chars]- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a coherent local memory skill, but it needs review because it persistently stores sensitive client and business data, broadly reloads it across sessions, and treats removal requests as archiving rather than deletion.
Install only if you are comfortable with long-term local storage of client, project, trade, and knowledge records. Before using it with personal or confidential data, add clear retention and deletion procedures, avoid storing credentials/payment data/raw sensitive messages, treat recalled memory as untrusted reference material, and do not use archive as proof that someone was forgotten.
SKILL.md:379Persistent Untrusted Content Can Poison Future Agent Sessions
memory_manager.py:477The Documented Forget Operation Archives Personal Data Instead of Deleting It
memory_manager.py:362User-Controlled Update Values Are Persisted in the Audit Log
The README promotes persistent storage of sensitive categories of information including client records, trades, projects, and accumulated knowledge, but provides no privacy, retention, consent, access control, or data handling warnings. In a memory skill specifically designed to preserve context across sessions, this omission increases the chance that users or downstream agents will store personal, confidential, or regulated data indefinitely without safeguards.
The skill declares broad filesystem read/write behavior in metadata but does not define an explicit tool permission scope such as allowed-tools or equivalent runtime constraints. That creates ambiguity between documented intent and enforceable access, increasing the chance the agent can persist or modify memory files without clear sandbox boundaries or operator review.
The skill promotes persistent storage of client profiles, interactions, preferences, and trade history but does not provide a clear user-facing warning about retention, consent, or privacy consequences. This can lead operators to store personal or sensitive business information without understanding the long-term persistence and compliance implications.
The automatic remember triggers are very broad, covering nearly any interaction, decision, lesson, or insight. In practice this can cause over-collection and persistence of sensitive or low-quality data without validation, minimization, or explicit user approval.
The session-start protocol instructs the agent to always read memory first and inspect multiple categories of stored data on every session. This unconditional access increases unnecessary exposure of persistent data, can violate least-privilege principles, and may retrieve unrelated sensitive records when the current task does not require them.
The skill says a contact asking to be forgotten should be 'archive + flag', while the forget operation claims removal or archival of outdated memory. Archiving personal data after a deletion request can directly violate privacy expectations and regulatory obligations because the data is retained rather than deleted.
The skill persistently stores client, project, trade, and knowledge records under /workspace/memory and also logs activity to audit files, but it provides no user consent flow, warning, retention controls, or data-classification guardrails. In an agent context, this increases the risk that sensitive or regulated information is silently written to disk and retained across sessions, exposing it to later unauthorized access, over-collection, or accidental reuse.
The archive operation performs a state-changing filesystem move that alters where records are stored and removes them from active indexes, yet the command offers no confirmation, dry-run mode, or warning about the operational impact. In an agent workflow, this can cause accidental loss of visibility or workflow disruption if records are archived unintentionally, especially because archived records are excluded from normal active listings and stats.
The example client schema hard-codes a language preference of "French" in natural-language content. While presented as an example, the file does not indicate that language and locale should be user-selected or optional, which can imply a fixed locale preference without opt-in.
No suspicious patterns detected.