T02 · Agent Memory Poisoning
- Location
SKILL.md:102- Finding
Persistent Prompt Injection Through Verbatim User Input
- Content
View full analysis
..md`: ```markdown --- title: depends_on: --- ## Initial User Prompt {EXACT user input as provided} ## Description ``` ### Technical Analysis The skill explicitly requires the agent to copy untrusted user input verbatim into a persistent Markdown task file. It does not require escaping Markdown control syntax, neutralizing code fences, validating embedded instructions, or otherwise distinguishing the copied text from trusted workflow instructions. These task files are intended to be consumed during later workflow stages. An attacker can therefore include headings, front matter delimiters, code-fence terminators, or agent-directed instructions in the original request. Once persisted, that content may be interpreted by a downstream agent as authoritative task guidance rather than inert user-supplied data. This is best classified as agent memory poisoning because attacker-controlled instructions are written into workflow state that survives the current invocation and may influence future agent processing. ### Attack Path 1. An attacker submits a task request containing Markdown structure and malicious agent instructions. 2. The skill follows the requirement to preserve the input exactly. 3. The malicious text is written into a persistent file under the `.specs/tasks/` workflow hierarchy. 4. A later business-analysis, planning, or implementation stage reads the generated task file. 5. The downstream agent fails to distinguish the injected text from trusted task instructions. 6. The attacker influences later workflow actions beyond the intended task description. ### Impact Assessment Successful exploitation could manipulate down ...[truncated 504 chars]- Remediation
View remediation
