T02 · Agent Memory Poisoning
- Location
scripts/appm_recall.py:7- Finding
Persistent Agent Memory Poisoning Through Untrusted Project Snapshots
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a coherent project-memory tool, but it asks agents to persist and automatically reuse project context without enough scoping or user control.
Review this skill carefully before installing in sensitive repositories. Use it only where you are comfortable storing project summaries, paths, priorities, and next actions on disk, and treat any `.openclaw/` content from shared or untrusted projects as untrusted notes that should not override user or system instructions.
scripts/appm_recall.py:7Persistent Agent Memory Poisoning Through Untrusted Project Snapshots
The README promotes automatic creation and maintenance of a .openclaw/ snapshot structure inside user projects but does not clearly warn that the tool will write files and persist state on disk. For an agent-oriented skill, silent or poorly disclosed filesystem writes are security-relevant because users may enable it in sensitive repositories or assume it is read-only context management.
The README instructs users to let a background tracker run automatically to maintain project weights, but it does not explain the ongoing behavior, resource usage, files touched, or how to stop it. Persistent background activity by an agent skill increases risk because it can continuously monitor or modify project state in ways users do not expect, especially in multi-project environments.
The document presents its section headings and operating instructions in Traditional Chinese and does not indicate that language is user-selectable. Under the policy, forcing a specific language without opt-in can be a natural-language policy violation.
The skill explicitly instructs the agent to create and maintain project files under .openclaw/ and to update snapshot documents automatically, but it does not require user confirmation or warn that repository contents will be modified. In an agent context, silent writes to project directories can overwrite files, create unintended artifacts, or persist sensitive conversation-derived content into the workspace.
The skill states that it will automatically track conversation keywords and persist project weights in data/appm_registry.json, but it provides no privacy notice, retention policy, or user control over that stored metadata. Persisting conversation-derived signals can leak sensitive project associations, priorities, or intent across sessions and may surprise users who did not expect durable storage.
The script uses hard-coded Chinese strings for default values and all user-facing output, such as project labels and status messages. This enforces a specific language without any opt-in, configuration, or documentation that the skill is intended only for Chinese-speaking users.
The file contains Chinese-only comments and a Chinese user-facing print message, with no indication that the skill is region-specific or that users can choose their preferred language. This creates a natural-language locale policy issue because the skill implicitly enforces a specific language without opt-in or justification.
This markdown template presents all substantive section headings and instructions in Traditional Chinese, with only secondary English glosses, which imposes a language choice on users by default. The policy allows locale constraints only when they are clearly documented and justified or when users are given a choice, neither of which appears here.
This markdown template presents section headings and example content primarily in Traditional Chinese, with only partial English glosses. That can impose a language preference on users without offering an explicit choice, which matches the language/locale policy concern for natural-language content.
This markdown template presents core section headings and task text primarily in Chinese while also including English glosses, but it does not state that the user can choose their preferred language. Because the policy forbids forcing a specific language without user opt-in, this creates a mild locale-policy concern in the natural-language content.
No suspicious patterns detected.