T02 · Agent Memory Poisoning
- Location
scripts/tools.py:219- Finding
Untrusted Content Can Be Promoted into Persistent Agent Memory
- Content
View full analysis
MAX_TOPIC_TOKENS: # Keep the newest content, truncate from the top new_content = _truncate_topic(new_content, MAX_TOPIC_TOKENS) topic_file.parent.mkdir(parents=True, exist_ok=True) topic_file.write_text(new_content, encoding="utf-8") ``` Topic content is then promoted into global memory: ```python # scripts/seal-worker.py:350-374 for topic_prefix in topic_prefixes: topic_file = TOPIC_DIR / f"{topic_prefix}.md" if topic_file.exists(): topic_content = topic_file.read_text(encoding="utf-8", errors="replace") # Extract just the key facts (headings + first lines) facts = _extract_key_facts(topic_content) if facts.strip(): combined += f"## {topic_prefix.title()}\n\n" combined += facts + "\n\n" if estimate_tokens(combined) > MAX_GLOBAL_TOKENS: combined = _truncate_global(combined, MAX_GLOBAL_TOKENS) if not dry_run: global_file.parent.mkdir(parents=True, exist_ok=True) ...[truncated 2517 chars]- Remediation
View remediation
