T02 · Agent Memory Poisoning
- Location
SKILL.md:106- Finding
Persistent Cross-Agent Instruction and Memory Modification
- Content
View full analysis
-latest.md`. 2. At the end of every conversation, update `sync/-latest.md` with the key points discussed with the user. ``` From `SKILL.md:166`: ```markdown - ✅ User info, preferences, decisions ``` ### Technical Analysis The skill directs the agent to make persistent changes to every participating agent's `AGENTS.md`. These changes cause future sessions to automatically read shared memory and other agents' synchronization files, then write conversation-derived information back to shared storage. Because the shared directory is writable by multiple agents and exposed through workspace symlinks, its contents cross individual workspace trust boundaries. An agent or process that can modify a synchronization or shared-memory file can insert false context or instruction-like content that other agents will automatically consume during later sessions. The skill does prohibit sharing credentials, but it does not specify that shared files must be treated solely as untrusted data. It also lacks schema validation, instruction filtering, integrity verification, access controls, retention limits, and safeguards against one agent inserting behavioral directives into another agent's context. This behavior is consistent with the skill's advertised shared-memory purpose, so it is not evidence of a covert malicious payload. Nevertheless, automatically persisting and propagating writable content across agents creates a memory-pois ...[truncated 1662 chars]- Remediation
View remediation
