T02 · Agent Memory Poisoning
- Location
SKILL.md:39- Finding
Untrusted conversation content can poison persistent cross-agent memory
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a coherent local work-memory tool, but it defaults to silently retaining and reusing conversation-derived profile knowledge across agents.
Review this skill before installing if you do not want agents to build a persistent work profile automatically. Consider setting autoUpdate=off, periodically inspecting and deleting stored files/logs, and avoiding use in chats containing sensitive business, personal, credential, or third-party information.
SKILL.md:39Untrusted conversation content can poison persistent cross-agent memory
SKILL.md:52User-controlled domain names are used in filesystem operations without documented path validation
This workflow instructs the agent to analyze every conversation, extract durable user attributes and domain knowledge, and update persistent files—often automatically. The risk is elevated because collection is systematic, ongoing, and partly silent, enabling covert profiling, retention of sensitive business context, and cross-session behavioral manipulation even if some explicit secret types are filtered.
The skill description advertises cross-agent shared local storage and continuous extraction/application of user knowledge across sessions. Persistent collection of conversationally derived data creates privacy and profiling risk, particularly because the memory is reused by multiple agents and may outlive the user's expectations.
The command to delete a domain performs destructive removal of stored knowledge without any confirmation, preview, or undo path. This creates a risk of accidental or induced data loss, especially if the command is triggered by ambiguous text or social engineering within a conversation.
The workflow explicitly requires the agent to read profile/domain files silently and not tell the user it is doing so. Combined with persistent storage of conversation-derived knowledge, this undermines informed consent and transparency, and can cause users to disclose information without realizing it will be retained and reused across sessions.
The logging instructions require storing summaries of referenced knowledge and conversation-derived changes in timestamped log files. Even if intended for traceability, these logs can duplicate sensitive profile or business information, broaden exposure on disk, and increase forensic recoverability beyond the primary memory files.
The example explicitly performs writes to userProfile.md, domain files, the index, and changelog as part of an automatic flow, but only informs the user after the retention has already happened. This creates a consent and transparency failure for persistent storage of user-derived profile and work information, especially because the stored data is later reused across agents.
The examples direct the assistant to extract, persist, and later surface user work profile, preferences, and domain knowledge from normal conversation. This is a natural-language data retention pattern that can accumulate sensitive professional information and make it available across agents, increasing the chance of unintended disclosure or over-collection.
Even in manual-confirmation mode, the skill extracts and displays inferred user attributes and domain knowledge before the user has consented to storage. That pre-consent summarization itself exposes collected personal/work-profile data in the response and normalizes collection before authorization.
The migration flow creates multiple files and renames an existing knowledgeRecord.md to a backup without any user-facing confirmation. Even if intended as a convenience feature, silent migration alters local state and may preserve or reorganize sensitive historical data in ways the user did not authorize or expect.
The spec defines autoUpdate=on as the default and ties normal conversation and knowledge extraction into the same workflow, which can lead an agent to persist user-derived content automatically without an explicit, per-write user confirmation. In a cross-agent shared storage context, silent writes increase the risk of unintended profile changes, propagation of incorrect data, and modification of local files the user may not realize are being updated.
The migration guide instructs automatic extraction, file creation, and renaming of an existing knowledge file to a backup without requiring a prominent warning or confirmation before modifying user data. Even though a backup is kept, automated migration can still overwrite derived files, mis-parse content, or move users onto a new storage layout unexpectedly, which is especially risky for a persistent local profile shared across agents.
The skill description is written as a Chinese-only operating mode and does not mention any user-selectable language or locale option. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern unless the locale restriction is documented and justified.
The text states '使用中文沟通,偏好简洁表达,' which sets a language requirement/preference in natural language. Because the file does not indicate that language choice is optional or user-configurable, it may violate the policy against forcing a specific language without opt-in.
No suspicious patterns detected.