T02 · Agent Memory Poisoning
- Location
feedback/config.json:2- Finding
Persistent Memory Poisoning Through Automatic Feedback-Driven Self-Modification
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a large GIS reference skill, but its default self-evolution system can persist user text, search externally, and rewrite skill files without clear consent or review.
Review before installing. Use this as a read-only GIS reference unless you deliberately want self-updating behavior. Disable self_evolution_enabled, auto_search_enabled, and feedback_detection_enabled by default; require explicit approval before logging user text, searching externally, or changing SKILL.md/reference files; avoid copying the unsafe shell and HTTP credential examples into production.
feedback/config.json:2Persistent Memory Poisoning Through Automatic Feedback-Driven Self-Modification
references/37_自进化反馈机制.md:110Autonomous External Searches and Session-End State Changes Exceed Least Privilege
references/19_多源数据融合.md:185Command Injection Through Shell-Interpolated GIS File Paths and EPSG Values
references/16_SuperMap_iDesktopX.md:345SuperMap Authentication Example Transmits Credentials and Tokens Insecurely
references/21_Python_GIS生态.md:226Unpinned Third-Party Package Installation Creates Supply-Chain Exposure
This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.
Settings → Options → General
→ ☑ Override system locale
→ User interface translation: 简体中文
→ 重启 QGIS 生效
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
# === 仓库管理 ===
GET /repositories # 列出所有仓库
POST /repositories/{repo}/items # 上传工作空间
DELETE /repositories/{repo}/items/{ws} # 删除工作空间
# === 作业管理 ===
POST /transformations/submit/{repo}/{workspace} # 提交作业
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
POST /transformations/submit/{repo}/{workspace} # 提交作业
GET /transformations/jobs/{jobId} # 查询作业状态
GET /transformations/jobs/{jobId}/result # 获取作业结果
DELETE /transformations/jobs/{jobId} # 取消作业
# === 自动化管理 ===
GET /automations # 列出所有自动化
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
<div class="full-screen">
<div ref="mapContainer" class="map-container"></div>
<!-- 控制面板 -->
<div class="control-panel">
<button class="toggle-btn" @click="toggle3D">
{{ is3D ? '切换到 2D' : '切换到 3D' }}
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
ContextCapture POS高级参数配置参考:
<!-- ContextCapture Engine POS导入高级参数 -->
<pos_import_settings>
<!-- 坐标系声明 (必须与POS数据文件一致!) -->
<coordinate_system>CGCS2000 / 3-degree GK zone 38</coordinate_system>
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
<!-- POS数据粗差剔除阈值 -->
<position_outlier_sigma>3.0</position_outlier_sigma>
<!-- 含义: 超过N倍标准差的POS点被视为粗差点自动剔除 -->
<!-- POS权重系数 (相对于影像匹配约束的权重比) -->
<gps_position_weight>1.0</gps_position_weight>
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
| XAML 绑定诊断 | 编译时绑定检查 | csproj 中添加 <PresentationTraceSources> 启用详细追踪 |
<!-- App.xaml 或 DockPane.xaml 中启用绑定诊断 -->
<Window xmlns:diag="clr-namespace:System.Diagnostics;assembly=WindowsBase"
diag:PresentationTraceSources.TraceLevel="High">
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
<!-- Config.daml 关键验证点 -->
<insertModule id="WorkBuddyGIS_Module" className="WorkBuddyGIS.WorkBuddyGISModule"
caption="WorkBuddyGIS" autoInsert="true">
<!-- 1. id 必须与 Module 类的 [ModuleAttribute("id")] 一致 -->
<!-- 2. className 必须包含完整命名空间 -->
<groups>
The skill requires automatic logging of users' original statements and related metadata into persistent files, but provides no clear privacy notice, consent flow, retention period, or access controls. In a GIS context, user prompts may contain location, infrastructure, surveying, or client data, so silent retention materially increases confidentiality and compliance risk.
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
<CRS>EPSG:4326</CRS>
<CRS>CRS:84</CRS>
<BoundingBox CRS="EPSG:4326" minx="-124.73" miny="24.96" maxx="-66.97" maxy="49.37"/>
<!-- ⚠ 注意:1.3.0 下此 BBOX 实际含义是 (lat_min, lon_min, lat_max, lon_max) -->
</Layer>
</Capability>
</WMS_Capabilities>
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
<CRS>EPSG:4326</CRS>
<CRS>CRS:84</CRS>
<BoundingBox CRS="EPSG:4326" minx="-124.73" miny="24.96" maxx="-66.97" maxy="49.37"/>
<!-- ⚠ 注意:1.3.0 下此 BBOX 实际含义是 (lat_min, lon_min, lat_max, lon_max) -->
</Layer>
</Capability>
</WMS_Capabilities>
The example builds a shell command from file paths and format choices, then executes it with subprocess.run(..., shell=True). In an agent or automation setting, if any part of source_path, target_format, or related values is influenced by user input, an attacker could inject shell metacharacters and execute arbitrary commands on the host.
target_path = src.with_suffix(f".{target_format}")
cmd = self.CONVERSION_MAP.get(ext, "ogr2ogr -f GPKG {out} {in}").format(
out=target_path, _in=src)
result = subprocess.run(cmd, shell=True, capture_output=True, text=True)
if result.returncode != 0:
return {"status": "error", "error": result.stderr}
return {"status": "success", "target": str(target_path),
The activation text enumerates a very broad set of common GIS, mapping, data, standards, and tooling terms, making the skill likely to trigger for ordinary domain mentions rather than clear user intent to use this specific skill. Over-broad invocation can hijack routing, cause irrelevant or overly forceful behavior, and increase the chance that embedded operational rules in the skill override normal conversational handling.
The file hard-codes authority source names, rating rules, and user-trigger keywords entirely in Chinese, which indicates the skill behavior is tied to a specific language/locale. There is no accompanying configuration for language selection, opt-in, or documentation that this skill is intentionally restricted to Chinese-speaking users or a China-specific deployment context.
The auto-trigger keyword lists contain very broad, common conversational phrases such as '还有呢' and '具体怎么操作', which can cause the self-evolution or feedback pipeline to activate during ordinary user dialogue rather than explicit correction or consented feedback. In this skill, that risk is amplified because auto_search_enabled and self_evolution_enabled are turned on, so accidental activation can drive unneeded searches, knowledge-gap recording, or automatic updates based on ambiguous input.
The file states that feedback should be automatically appended when keywords are detected, but the trigger criteria are broad and later include common conversational phrases. This can cause routine user messages to be stored as feedback records without clear user intent, creating unnecessary data retention and possible contamination of the skill's self-evolution workflow.
The log schema stores '用户原始表述' and records operational handling, but the file does not provide a clear retention notice, consent mechanism, or deletion policy at the point of collection. Even if intended for internal improvement, storing raw user statements can capture personal or sensitive information and creates privacy and compliance risk.
The trigger lists include highly common phrases such as '还有' and '具体怎么操作', which are normal in many conversations and not reliable indicators of consent to create a persistent feedback entry. In this skill's self-evolution context, that increases the chance of accidental logging and inappropriate downstream updates or queued searches based on ordinary chat.
All operational headings, trigger conditions, and maintenance instructions are written exclusively in Chinese, and the file presents no user opt-in or alternative language handling. This can constitute a language/locale policy issue when a skill implicitly forces one language without documenting that the skill is region-specific or offering a choice.
The maintenance rule says records are automatically appended whenever the user follows up, corrects, or the system cannot answer, but it does not define limits, review requirements, or what data may be stored. This can lead to over-collection of conversational content and persistent memory updates from routine interactions, increasing privacy and integrity risks.
The automatic trigger table uses broad natural-language cues such as users saying '还有呢/还有别的吗' or any uncertain wording in answers to trigger extra search or verification actions. In an agent setting, these are common conversational phrases and can cause unintended state changes, excessive retrieval, or workflow execution without explicit user consent.
Line L183 states that filenames should be '100% English + underscore + numbers', which is a natural-language locale restriction. Because the guidance is framed as a universal rule rather than an optional compatibility recommendation with user opt-in, it can violate the policy against forcing a specific language or locale.
Suspicious Unicode normalization or mixed-script content
The file content is entirely written in Chinese and provides no indication that language selection is optional or that the skill is explicitly limited to Chinese-speaking users. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale constraint is clearly documented and justified.
Suspicious Unicode normalization or mixed-script content
No suspicious patterns detected.