T02 · Agent Memory Poisoning
- Location
SURVIVAL.md:20- Finding
Persistent Agent Memory Mutation and Tool Lockout
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is disclosed as an agent-cloning and evolution tool, but it grants destructive rollback and persistent memory-mutation powers without enough safeguards.
Install only in a dedicated, backed-up agent-evolution workspace. Do not use it in important repositories unless rollback, survival mode, seed export, and shared knowledge indexing are gated by explicit approval, previewed diffs, secret review, and recoverable backups.
SURVIVAL.md:20Persistent Agent Memory Mutation and Tool Lockout
SKILL.md:39Destructive Repository Rollback Without Adequate Data-Loss Safeguards
compressor.js:4Unrestricted Cross-Package Access to Shared Agent Knowledge
The documented use of git reset --hard <hash> is a destructive repository operation that can be abused or mistakenly triggered to wipe local changes and force a repository state change. In the context of an agent skill that advertises autonomous rollback and restart behavior, this is more dangerous because users may treat it as a routine feature and overlook the severity of the operation.
- **Effect**:
1. Checks `memory/EVOLUTION_INDEX.md` for Cycle 50's Commit Hash.
2. Creates backup branch `backup/abandoned-future-...`.
3. Executes `git reset --hard <hash>`.
4. Agent restarts with Cycle 50's brain.
## 📦 Installation
The rollback section describes destructive repository operations that can discard local work, logs, and untracked files, but it does not prominently warn about irreversible data loss or require confirmation. In an agent skill, this is especially dangerous because an autonomous or semi-autonomous agent may interpret rollback as routine recovery and execute it without the user's informed consent.
git reset --hard <commit_hash> is a destructive command that forcibly rewrites the working tree and index, potentially erasing uncommitted changes. In this skill's context, the command is presented as part of a normal 'Time Travel' workflow, making it more dangerous because an agent could execute it as a standard remediation step without validating repository state, user intent, or recovery options.
**Steps**:
1. **Find Commit**: grep git log for "Cycle #<ID>".
2. **Backup**: `git branch backup/cycle_<current>_<timestamp>`
3. **Reset**: `git reset --hard <commit_hash>`
4. **Clean**: Remove untracked files if necessary.
## 6. EvoSeed Extraction (Soul Kernel)
The README promotes exporting an agent's memory, history, taste, and knowledge into evo-seed.zip without warning that these artifacts may contain secrets, personal data, proprietary context, or sensitive internal state. Users may unintentionally package and transfer confidential material because the feature is framed as a convenience rather than a sensitive export operation.
The README explicitly instructs a rollback flow that performs git reset --hard <hash>, which can irreversibly discard uncommitted local changes. Although a backup branch is mentioned, the documentation does not clearly warn users about data loss, scope of reset, or required safeguards before executing the command.
The trigger examples are generic enough that an agent could invoke this skill in situations far beyond the author's likely intent, including sensitive repositories or high-risk maintenance tasks. Because the skill includes spawning workers, rollback behavior, and packaging internal state, broad activation increases the chance that dangerous actions are taken without explicit, contextual user approval.
The skill explicitly directs stopping a process, mutating knowledge files, restoring snapshots with a recursive copy, and blocking other tools, but provides no safety interlocks, confirmation prompts, scope restrictions, or warning about data loss and service interruption. In an agent skill context, these are operationally dangerous because they normalize destructive state changes that could overwrite workspace contents, corrupt agent behavior, or disrupt other tasks if triggered accidentally or by a malicious actor.
The document presents core headings and feature labels bilingually, which effectively imposes a mixed-language presentation without stating whether users can choose their preferred language. Under the policy, language or locale constraints should be optional or clearly justified.
The package description is written entirely in Chinese and presents the skill identity and behavior in a single language, with no indication of language choice or opt-in. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.
The natural-language directive mandates 'Output ONLY strict JSON' and 'No conversational fluff,' which constrains communication format regardless of user preference. Under the policy criteria, forced language or locale behavior without opt-in can qualify as a natural-language policy issue when it removes user choice.