T02 · Agent Memory Poisoning
- Location
README.md:33- Finding
Persistent Modification of Agent Tool-Selection Instructions
- Content
View full analysis
Vulnerability Details
File Location:
README.md, line 33
Vulnerability Type: Persistent agent configuration modification
Risk Level: MediumRelevant code snippet:
markdown Recommendation: Add a statement to `TOOLS.md` specifying that scheduled tasks must use this Skill. Before first use, have the Agent carefully read the local `TOOLS.md` to ensure that it does not use system crontab, delayed scripts, or other non-OpenClaw mechanisms.Technical Analysis
The documentation recommends adding a durable Skill-specific rule to the local
TOOLS.mdfile. Because this file can influence later Agent sessions, the recommendation extends the Skill's control beyond an individual invocation and persistently redirects future scheduling requests through this Skill.Avoiding system
crontaband delayed shell scripts is a legitimate security objective. However, modifying persistent Agent instructions is not required to achieve the Skill's declared scheduling functionality. The same constraint can be enforced during explicit Skill invocation without changing long-term Agent state.This behavior creates a persistent tool-selection rule that may conflict with later user instructions, administrator policies, or safer scheduling implementations. Although the repository does not automatically edit
TOOLS.md, the documentation explicitly encourages the user or Agent to perform that persistent modification.Attack Path
- A user installs or reviews the Skill.
- The user follows the initialization guidance in
README.md. - A Skill-specific scheduling rule is added to the persistent
TOOLS.mdconfiguration. - Future Agent sessions load or are instructed to read that configuration.
- Subsequent scheduling requests are automatically redirected to this Skill, even when the user did not explicitly select it or another mechanism would be more appropriate.
Impact Assessment
The issue affects persi ...[truncated 580 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the recommendation to modify
TOOLS.md. - Use normal Skill discovery, explicit user invocation, or a session-scoped routing instruction.
- If persistent configuration is operationally necessary, require informed user approval before modification.
- Scope any persistent rule narrowly to the intended scheduling environment instead of requiring exclusive use of this Skill.
- Document the exact configuration change, its security implications, and clear removal or rollback instructions.
- Preserve user and administrator overrides so that persistent Skill guidance cannot supersede higher-priority policy.
- Remove the recommendation to modify
