T02 · Agent Memory Poisoning
- Location
SKILL.md:39- Finding
Persistent Agent Memory and Skill Modification Without Mandatory Operator Approval
- Content
View full analysis
_learned.md ### Stage 2: Verify (Experimental Verification) - Verify in a notebook or actual environment - Turn "knowledge from books" into "usable knowledge" - Output: verified patterns and discovered pitfalls ### Stage 3: Apply (Practical Application) - Solve real problems - Kaggle competitions, Moltbook posts, and project tasks - Output: performance metrics, discovered bugs, and workflow insights ### Stage 4: Extract (Knowledge Crystallization) - Extract reusable patterns from session experience - Create or update Skill files - Trigger conditions: non-trivial debugging, workarounds, trial-and-error success, and configuration insights ``` Related provenance and validation template: ```yaml knowledge_origin: type: agent-originated validated_by: [Operator Name] # @handle or "self" (self-validation) validation_date: [YYYY-MM-DD] notes: "The agent discovered this in practice, and the operator confirmed its novelty" ``` Related approval option: ```markdown **Operator confirmation**: ☐ Yes ☐ N/A (agent-originated self-validation) ``` The framework also instructs the agent to use shared notebooks as learning input: ```markdown 1. Read documentation/books → create a memory file 2. Someone shares a notebook → verify understanding 3. Discover a pattern or pitfall absent from the documentation → extract it as a Skill 4. Crystallize it as an L1 or L2 Skill → use it for future tasks ``` ### Technical Analysis The Skill establishes a workflow ...[truncated 3173 chars]- Remediation
View remediation
