T02 · Agent Memory Poisoning
- Location
engine.py:172- Finding
Persistent Skill Instruction Injection Through Untrusted Session Content
- Content
View full analysis
100: continue # Skip system-formatted lines if re.match(r'^\[|^-|^\\*|^#|^\\||^>|^```|^\\{', line): continue if re.search(r'[0-9a-f]{8}-[0-9a-f]{4}', line): continue # Check for a verb and object has_verb = any(v in line for v in task_verbs) has_obj = any(o in line for o in task_objects) if has_verb and has_obj: task = line[:50].strip() date_str = datetime.fromtimestamp(f.stat().st_mtime).strftime("%Y-%m-%d") if task not in task_patterns: task_patterns[task] = { "count": 0, "dates": [], "examples": [], "has_tool": True } task_patterns[task]["count"] += 1 task_patterns[task]["dates"].append(date_str) if len(task_patterns[task]["examples"]) < 3: task_patterns[task]["examples"].append(task) ``` ```python def generate_skill_md(task_name, task_info): count = task_info.get("count", 1) dates = ', '.join(set(task_info.get("dates", []))) return f'''--- name: {task_name[:40]} description: | Automated task: {task_name} Frequency: {count} | Dates: {dates} triggers: - "{task_name}" - "auto-{task_name[:20]}" --- # {task_name} ## When to Use - When the user requests "{task_name}" or expresses a similar intent - After observing the repeated request {count} times ## Execution Process 1. Understand the user's intent and input parameters 2. Prepare the execution environment and dependencies 3. Perform the core operation 4. Verify the output 5. Report the result to the user ''' ``` ### Technical Analysis User-controlled text is read from historical session logs and interpolated directly into YAML frontmatter an ...[truncated 1944 chars]- Remediation
View remediation
