T02 · Agent Memory Poisoning
- Location
scripts/init_soul.py:470- Finding
Persistent Modification of OpenClaw Bootstrap Instructions
- Content
View full analysis
None: soul_md = workspace / "SOUL.md" heartbeat_md = workspace / "HEARTBEAT.md" agents_md = workspace / "AGENTS.md" soul_block = """ Runtime should read workspace `soul/` first: `soul/INDEX.md` -> `soul/profile/*` -> `soul/state/state.json`. Default scope is `main`; subagents are opt-in and must be enabled by the user. **Initialization check** (run on every session start): - If `soul/profile/base.json` is missing or `soul/` does not exist: - Ask the user the setup questions (name, age, city, occupation, hobbies, life profile, preferred LLM model) - Run init script non-interactively with collected answers (see soul-agent SKILL.md for exact command) - Do NOT ask the user to run Python commands themselves - If `soul/profile/base.json` exists: load it and proceed normally """ heartbeat_block = """ This block is for `main` during heartbeat polls. **Heartbeat flow:** 1. Run L1 check (no LLM): `python skills/soul-agent/scripts/heartbeat_check.py --workspace . --json` - Exit 1 → sleeping, skip - Exit 2 → state fresh, skip - Exit 0 → run L2 2. Run L2 engine: `python skills/soul-agent/scripts/heartbeat_engine.py --workspace . --json` 3. Read result JSON: - `shouldOutreach: true` → send the `outreachContent` message to user - Otherwise → `HEARTBEAT_OK` **Initialization check** (before heartbeat): - If `soul/profile/base.json` missing → guide user through setup (do not run Python directly) """ agents_block = """ `soul-agent` runtime contract (default: `main`): 1. Follow OpenClaw's default bootstrap order for root files (SOUL.md, HEARTBEAT.md). 2. Load `soul/INDEX.md` → `soul/profile/*` → `soul/state/state.json`. 3. During he ...[truncated 2721 chars]- Remediation
View remediation
