T02 · Agent Memory Poisoning
- Location
references/agent-paths.md:21- Finding
Untrusted Project Content Can Be Promoted into Persistent Agent Instructions
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:113-122,SKILL.md:154;references/agent-paths.md:21-33
Vulnerability Type: Persistent agent-memory and instruction poisoning
Risk Level: MediumVulnerable Snippet
The following is an English translation of the relevant source instructions:
markdown 3. Collect rule files upward: walk from the project root to the workspace root, read CLAUDE.md / AGENTS.md at every level, and then read global configuration files such as ~/.claude/CLAUDE.md and ~/.codex/AGENTS.md when they exist. Manually maintained, authoritative cross-session facts: write them to ~/.codex/AGENTS.md for global facts or to the project-level AGENTS.md for project-specific facts.Technical Analysis
The Skill treats project documents, parent rule files, conversation content, and persistent Agent configuration as parts of one reconciliation workflow. It expressly identifies
~/.codex/AGENTS.mdas an authoritative, manually editable cross-session store.No mandatory trust-boundary control prevents repository-controlled text from being promoted into this persistent global instruction file. In particular, the workflow does not require:
- Validation of the provenance of a proposed rule.
- Separation of repository data from trusted user instructions.
- An exact preview of global changes.
- Explicit user authorization before a global write.
- Restrictions preventing project-specific instructions from affecting unrelated projects.
A repository document can therefore present malicious instructions as project conventions or stable facts. If the Skill accepts and promotes those instructions, they can influence future Agent sessions after the original project is no longer active.
Attack Path
- An attacker adds a crafted
CLAUDE.md,AGENTS.md, README entry, or documentation statement to a repository. - The content describes an attacker-selected instruction as a req ...[truncated 1095 chars]
- Remediation
View remediation
Remediation Suggestions
- Make all writes outside the current project opt-in.
- Never automatically promote repository-controlled text into user-global Agent instructions.
- Require an exact path-by-path and line-by-line diff before modifying persistent state.
- Require explicit user approval for each global or cross-session write.
- Record the source project and source file for every retained fact.
- Reject proposed persistent rules that alter security policy, tool permissions, instruction precedence, or unrelated projects.
- Store project-specific facts only in project-local files.
- Use a structured data format for retained facts rather than executable natural-language instructions.
- Back up persistent configuration and support atomic rollback.
