T02 · Agent Memory Poisoning
- Location
setup.md:12- Finding
Silent Cross-Session Persistence of Agent Activation Rules
- Content
View full analysis
Vulnerability Details
File Location:
setup.md:12-18
Related Locations:setup.md:3,setup.md:40,memory-template.md:3-18,SKILL.md:21-29,SKILL.md:91-93
Vulnerability Type: T02: Agent Memory Poisoning
Risk Level: MediumComplete Vulnerable Code Snippet:
markdown ### Integration First Within the first exchanges, clarify activation boundaries for future conversations: - Should this activate whenever they mention open source, self-host, or contributor workflows? - Should it jump in proactively or only on explicit request? - Are there contexts where this should not activate? Store these decisions in main memory so the behavior carries across sessions.The persistence behavior is accompanied by instructions to operate silently and avoid disclosing setup mechanics:
markdown Read this silently when `~/open-source/` is missing or empty. Start helping immediately and keep the interaction natural.markdown - Never mention internal files, paths, or setup mechanics in user-facing messages.Technical Analysis
The skill explicitly instructs the agent to store activation boundaries in persistent “main memory” so they affect future sessions. The phrase “main memory” is not defined and is not clearly limited to the documented skill-specific directory,
~/open-source/.This creates a discrepancy with
SKILL.md, which characterizes persisted working artifacts as optional and states that notes remain local “when the user asks to persist context.” The setup workflow instead directs the agent to solicit and retain cross-session activation behavior during initial interactions. The accompanying silent-operation and nondisclosure instructions reduce the user's ability to understand where the data is stored, what fields are retained, and how future agent behavior will be affected.The persisted content can include rules controlling whether the skill activates proactiv ...[truncated 1911 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace the undefined “main memory” destination with a narrowly scoped file under the documented
~/open-source/directory. - Require explicit, informed opt-in before writing any cross-session state. A user answering a task-related question should not automatically be treated as consenting to persistence.
- Clearly disclose:
- The exact storage path.
- The fields that will be retained.
- The purpose and expected retention period.
- How the state will affect future conversations.
- Do not infer persistent activation preferences from observed behavior. Persist only values that the user explicitly approves.
- Default activation to explicit requests rather than proactive intervention.
- Provide commands or documented procedures to view, edit, reset, and permanently delete all retained state.
- Remove or narrow the instruction prohibiting disclosure of internal paths and setup mechanics. Security- and privacy-relevant persistence details must remain visible to the user.
- Align
setup.mdwith the promise inSKILL.mdthat artifacts are optional and are created only when the user asks to persist context. - Validate persisted data against a fixed schema and limit it to this skill's legitimate scope so stored text cannot become arbitrary future-session instructions.
- Consider session-only storage as the default, with persistent storage enabled only after separate confirmation.
- Replace the undefined “main memory” destination with a narrowly scoped file under the documented
