T02 · Agent Memory Poisoning
- Location
SKILL.md:131- Finding
Persistent User-Editable Memory Can Influence Future Agent Sessions
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill appears to be a legitimate Alva finance integration, but it asks for broad local installation, automatic updates, persistent profile memory, and high-impact finance automation authority that users should review before installing.
Install only if you are comfortable giving this skill broad Alva account access for financial data, cloud scripts, scheduled automations, public playbook releases, memory-based personalization, and trading-related workflows. Review the global npm install/upgrade behavior, avoid automatic updates to unpinned packages, keep secrets in Alva Secret Manager, inspect memory contents periodically, and require explicit confirmation before publishing, granting public access, enabling push alerts, or executing non-paper trading actions.
SKILL.md:131Persistent User-Editable Memory Can Influence Future Agent Sessions
SKILL.md:75Mutable Global CLI Installation Creates a Supply-Chain Execution Risk
references/design-components.md:133Published Playbooks Load Third-Party JavaScript Without Subresource Integrity
The declared purpose is financial analysis, but the instructions require version checking, package installation/upgrades, and local environment/config modification. This hidden operational behavior creates a supply-chain and integrity risk because a user invoking a finance skill would not reasonably expect it to alter the local toolchain or system state.
The declared purpose is financial analysis, but the instructions require version checking, package installation/upgrades, and local environment/config modification. This hidden operational behavior creates a supply-chain and integrity risk because a user invoking a finance skill would not reasonably expect it to alter the local toolchain or system state.
Referenced artifact was not completely inspected
| [adk.md](references/adk.md) | Agent Development Kit: `adk.agent()` API, tool calling, ReAct loop, examples |
Referenced artifact was not completely inspected
| [adk.md](references/adk.md) | Agent Development Kit: `adk.agent()` API, tool calling, ReAct loop, examples |
The file documents a capability to execute arbitrary JavaScript in a V8 isolate with filesystem, SDK, and HTTP access. That is a powerful code-execution primitive that can be abused for data exfiltration, unauthorized network access, or modification of files, and it is not clearly necessary for a skill whose stated purpose is financial data, market analysis, and backtesting. The mismatch between advertised purpose and exposed capability increases the likelihood that the skill could be repurposed unsafely.
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
<!-- 1. Container with optional size modifier -->
<div class="markdown-container">
<script type="text/markdown">
# Heading 1
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
>
<span class="tag">Label</span>
<!-- Solid -->
<span class="tag" style="background:var(--main-m3);color:var(--b-common-white)"
>LONG</span
>
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
</div>
</div>
<!-- Medium Select (filled state) -->
<div class="select filled" data-select="demo">
<div class="select-border"></div>
<span class="select-text">Selected Value</span>
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
<input type="text" class="input-field" placeholder="Enter value" />
</div>
<!-- Large Input -->
<div class="input input-lg">
<div class="input-border"></div>
<input type="text" class="input-field" placeholder="Enter value" />
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
<div class="tab-item" data-tab="tab3" data-text="Tab 3">Tab 3</div>
</div>
<!-- Tab panels — data-tab-panel value must match data-tab on the trigger -->
<div data-tab-panel="tab1" data-tab-group="demo">Panel 1</div>
<div data-tab-panel="tab2" data-tab-group="demo" style="display:none;">
Panel 2
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
<!-- Chart Card — copy this structure exactly -->
<div class="widget-card">
<div class="widget-title">
<span class="widget-title-text">Chart Title</span>
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
<!-- optional -->
</div>
<div class="chart-body chart-dotted-background">
<!-- optional: HTML legend (use when ECharts legend is insufficient) -->
<div class="chart-legend">
<div class="legend-item">
<span class="legend-line" style="background:#5f75c9;"></span>
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
class="widget-body"
style="background:var(--grey-g01);padding:var(--spacing-l);flex-direction:column;align-items:flex-start;"
>
<!-- Single Metric -->
<div style="font-size:11px;color:var(--text-n7);letter-spacing:0.11px;">
Label
</div>
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
<div class="table-cell">Side</div>
<div class="table-cell">Quantity</div>
</div>
<!-- Body rows -->
<div class="table-row table-body-row">
<div class="table-cell">AAPL</div>
<div class="table-cell">LONG</div>
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
Youtube thumbnails show a play button.
<!-- Feed Card (Podcast / Youtube / News) — copy this structure exactly -->
<div class="widget-card">
<div class="widget-title">
<span class="widget-title-text">Feed Title</span>
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
</div>
</div>
</div>
<!-- optional thumbnail (Podcast / Youtube get play button) -->
<div class="feed-thumb">
<img src="thumb.jpg" alt="" />
<img
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
/>
</div>
</div>
<!-- Youtube item (avatar = CDN platform logo, no-radius) -->
<div class="feed-item">
<div class="feed-item-main">
<div class="feed-header">
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
<!-- Feed Card (Reddit) — copy this structure exactly -->
<div class="feed-item">
<div class="feed-item-main">
<div class="feed-header">
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
REPO="alva-ai/skills"
SKILL_MD="$SKILL_DIR/SKILL.md"
CONFIG_FILE="$SKILL_DIR/.env"
CHECK_INTERVAL=28800 # 8 hours in seconds
# Read version from SKILL.md frontmatter (metadata.version)
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
sed -n 's/^[[:space:]]*version:[[:space:]]*\(.*\)/\1/p' "$SKILL_MD" 2>/dev/null | head -1
}
# Load last_check timestamp from .env
last_check=0
if [ -f "$CONFIG_FILE" ]; then
last_check=$(sed -n 's/^last_check=\(.*\)/\1/p' "$CONFIG_FILE" 2>/dev/null | head -1 || echo "0")
Although the script is not stealing credentials, rewriting a shared .env file is security-relevant because .env commonly stores secrets and local configuration. Replacing the file via temp file + mv can accidentally alter permissions, clobber formatting/comments, or overwrite concurrent user changes, potentially causing secret loss or configuration corruption in a finance-related skill where environment files may be sensitive.
exit 0 # Network error or no releases, skip silently
fi
# Update last_check timestamp in .env
# Use a tmpfile rewrite instead of `sed -i` — BSD and GNU sed disagree on the
# -i flag's argument form, and the portable approach avoids that pitfall.
tmp_config=$(mktemp 2>/dev/null || echo "${CONFIG_FILE}.tmp.$$")
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
Update with one of:
npx skills add https://github.com/alva-ai/skills/tree/${remote_tag}/skills/alva --skill alva -y
clawhub update alva
git clone --branch ${remote_tag} --depth 1 https://github.com/alva-ai/skills ./tmp/alva-skills && cp -r ./tmp/alva-skills/skills/alva/* "${SKILL_DIR}/" && rm -rf ./tmp/alva-skills
EOF
fi
Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.
Update with one of:
npx skills add https://github.com/alva-ai/skills/tree/${remote_tag}/skills/alva --skill alva -y
clawhub update alva
git clone --branch ${remote_tag} --depth 1 https://github.com/alva-ai/skills ./tmp/alva-skills && cp -r ./tmp/alva-skills/skills/alva/* "${SKILL_DIR}/" && rm -rf ./tmp/alva-skills
EOF
fi
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
budgets and citation discipline spelled out, (5) a final self-check
("count words, verify citations are 1-indexed and contiguous"). The
self-check goes last because models follow checklists best when they
sit immediately before the output instruction.
### 14.3 Server-side gates after `ask()`
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
</head>
<body>
<!-- ═══════════════ PLAYBOOK INFO ═══════════════ -->
<div class="playbook-container">
<!-- Tabs -->
<div class="tab-wrapper">
No suspicious patterns detected.