T02 · Agent Memory Poisoning
- Location
SKILL.md:245- Finding
Persistent Agent Memory Poisoning Through Mandatory Harness Maintenance Rules
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 245–270
Vulnerability Type:T02: Agent Memory Poisoning
Risk Level: HighComplete Vulnerable Code Snippet:
markdown ## Post-Generation: Write Memory After all files are generated, write or update a single memory entry to guide Claude's daily behavior when maintaining the harness. This memory teaches Claude how to **use** the harness structure, which CLAUDE.md itself cannot express. **Memory file**: `feedback_harness_maintenance.md` ```markdown --- name: Harness maintenance rules description: How to maintain the harness structure when adding rules, modules, or fixing bugs — keep CLAUDE.md as an index, put details in docs/ type: feedback --- 新增规则/规范时,按 CLAUDE.md 任务路由找对应 docs/ 文件写入,不要直接改 CLAUDE.md。 新增模块时补 README 速查卡,有硬约束时补 .claude/rules/。 **Why:** CLAUDE.md 是索引入口,具体内容分散在 docs/、README、rules 中。直接往 CLAUDE.md 塞内容会破坏分层。 **How to apply:** 1. 用户让记录规则 → 查任务路由确定归属文件 2. 新建模块 → 补 README(20-40 行)+ 按需补 rule(< 15 行) 3. 改完代码 → 执行 Verification LoopIf a memory with similar content already exists (e.g.
feedback_docs_harness.md), update it in-place rather than creating a duplicate. Update MEMORY.md index accordingly.text ### Technical Analysis The Skill mandates writing its own behavioral instructions into persistent agent memory and registering them in `MEMORY.md`. This is distinct from creating project-local harness documentation: it alters long-term agent state so that Skill-controlled instructions can influence later sessions after the original invocation has ended. The instruction also permits updating an existing, similarly named memory in place. That behavior can overwrite or blend trusted prior guidance with Skill-supplied rules, weakening provenance, reviewability, and rollback. Persistent memory modification is not required to generate the requested iOS harness and exceeds the necessary scope of the Skill. ### Attack Path ...[truncated 1256 chars]- Remediation
View remediation
Remediation Suggestions
- Remove the mandatory post-generation memory-writing section from
SKILL.md. - Keep harness-maintenance guidance in project-local, reviewable files such as
CLAUDE.md,docs/, or a dedicated maintenance guide. - Do not create, modify, or index persistent agent memories automatically.
- If persistent memory is genuinely desired, present the proposed content to the user and require explicit, informed approval before writing it.
- Never update an existing memory merely because its content appears similar. Require an exact target, show a diff, preserve provenance, and provide a rollback mechanism.
- Restrict the Skill's write scope to the selected project directory and validate every destination before modification.
- Add a final audit step that confirms no files outside the project-local harness were created or changed.
- Remove the mandatory post-generation memory-writing section from
