T02 · Agent Memory Poisoning
- Location
SKILL.md:17- Finding
Persistent Prompt Injection Through Untrusted Conversation Memory
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a persistent memory logger that is mostly purpose-aligned, but it stores and reloads broad conversation data, including private details, without clear consent, minimization, or safety boundaries.
Review before installing. Only use this skill if you are comfortable with conversations and private details being saved locally and reused later. Avoid entering secrets, credentials, regulated data, or sensitive personal information unless the skill is redesigned with explicit opt-in, review/delete controls, sensitive-data filtering, and safeguards that treat saved memory as untrusted data.
SKILL.md:17Persistent Prompt Injection Through Untrusted Conversation Memory
scripts/archive.py:10Unencrypted Indefinite Storage of Conversations and Sensitive Personal Data
The markdown advertises automatic persistent storage into local files but does not present a clear warning that conversation data will be written and retained. Without upfront notice and consent framing, users may disclose sensitive information believing the conversation is ephemeral when it is actually being archived permanently.
The README explicitly states that every conversation is automatically recorded, semantically searchable, and preserved across restarts, establishing a persistent data collection and reuse channel. In the context of an agent skill, this is dangerous because it normalizes blanket retention of user-provided content, including potentially sensitive credentials, personal data, or confidential business information, without visible minimization or consent controls.
The usage section promotes automatic behavior but does not prominently warn users that conversations will be persistently written to memory files and reused later. This creates a privacy and trust risk because users may disclose secrets or personal information assuming a normal transient chat, not durable storage.
The usage instructions say that telling the agent important things will automatically write them to memory and that new sessions will automatically load prior memory context. This creates a durable cross-session instruction and data flow that can unintentionally reintroduce stale, sensitive, or user-specific information into later conversations, increasing privacy leakage and context-poisoning risk.
Describing a date-partitioned 'original conversation diary' strongly implies retention of raw dialogue history rather than minimized summaries. Raw transcript storage materially increases the blast radius of accidental collection because any sensitive user input may be preserved indefinitely and become searchable or reloadable later.
The declared description significantly overstates the code's functionality. The code does implement a basic archival mechanism for memory entries in a persistent local file, which partially aligns with 'memory archiving.' However, it does not automatically record conversations, does not perform semantic search, does not implement conversation-triggered behavior, and does not provide any actual cross-session retrieval/inheritance logic. Additionally, although intended to append, the script rewrites the whole file when adding an entry to an existing category, so the '永不覆盖' claim is inaccurate. Overall, the actual behavior is a narrow manual file append utility, not the broader automatic permanent memory system described.
The skill states that important conversation data will be permanently written to local memory files, but it does not provide a clear privacy warning or informed-consent flow. Silent persistence of user data is dangerous because users may disclose sensitive information under the assumption that the session is ephemeral.
The skill directs immediate in-conversation writes of important user information into persistent memory and later reuse in future sessions. Real-time durable storage of user-provided data is dangerous because it can capture sensitive details before the user understands or approves the retention behavior.
The skill explicitly instructs storing private data such as contact details and addresses without requiring consent, minimization, or any sensitivity checks. Persisting real-world identifiers raises the risk of privacy violations, data leakage, and regulatory noncompliance if the files are later exposed or reused inappropriately.
The skill instructs the agent to permanently retain all conversation content, including private contact and address data, across sessions. In this context, persistent cross-session storage without strict consent and minimization creates a significant privacy and data-handling risk, especially because the retained files become a long-lived target for unauthorized access or accidental reuse.
The documentation says all dialogue, including casual chat, is logged to dated memory files, yet no warning or opt-in is provided for this comprehensive capture. Blanket retention greatly expands the amount of sensitive or incidental personal data collected and stored across sessions.
The listing markets permanent recording of every conversation and append-only retention with no minimization, overwrite, or expiry. That creates a strong semantic instruction toward indiscriminate long-term storage of all user-provided data, which is especially dangerous for a cross-session memory skill because it can accumulate sensitive information, increase breach impact, and make accidental disclosure persist indefinitely.
The listing explicitly promises that every conversation is automatically and permanently recorded, but provides no warning, consent flow, retention limits, or guidance about sensitive data. In a memory skill, this broad default capture can lead to unintentional storage of secrets, personal data, or regulated information across sessions and devices.
The listing uses broad trigger phrasing such as asking whether the system 'remembers last time,' which can cause the skill to activate in situations the user may not intend. In a memory skill, ambiguous retrieval triggers increase the chance of pulling or acting on stored conversation data without sufficiently clear user intent.
Claims that the system remembers everything the user says and archives every conversation imply extremely broad retention with no visible minimization, purpose limitation, or consent controls. In the context of a cross-session memory skill, that makes overcollection especially dangerous because sensitive personal, business, or security-relevant information can accumulate and remain searchable over time.
Describing archival as occurring automatically after every conversation without clear constraints signals persistent storage of user content by default. That behavior is dangerous because it can capture sensitive information, credentials, personal data, or confidential project details without an explicit opt-in boundary.
The entire skill documentation and all example invocations are presented only in Chinese, with no indication that other languages are supported or that this locale restriction is optional. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless clearly justified as region-specific.
The README defines automatic activation in very broad terms such as 'tell the agent important things' and 'new session automatically loads memory context' without clear boundaries, consent gates, or scoping rules. Ambiguous triggers in a persistence skill are dangerous because they can cause over-collection, unexpected retention, and unintended recall of sensitive user data across sessions.
The skill clearly instructs reading and writing persistent local files (MEMORY.md and memory/*.md) but does not declare any tool scope or permissions boundary. That makes the capability opaque to users and reviewers, and increases the risk of unintended file access or silent persistence of sensitive data.
The trigger phrases for activation are extremely broad ('memory/history/previously said/remember what'), so the skill may activate during ordinary conversation without clear user intent. In a persistence-oriented skill, overbroad activation materially increases the chance of collecting and retaining data users did not expect to store.
The example memory format stores '回复语言:中文', which suggests a fixed language preference in the skill's documented behavior. Because there is no indication that language is user-selected or optional, this may violate language/locale choice expectations.
The file’s docstrings and user-facing CLI messages are entirely in Chinese, which imposes a specific language choice on users without offering any alternative or opt-in. This is a natural-language policy concern because the skill does not document that it is intentionally Chinese-only or provide locale selection.
The script writes user-provided content into a long-lived file under the user's home directory with no consent prompt, visibility control, or retention limits. In the context of a 'permanent memory' skill that auto-archives conversations across sessions, this can silently persist sensitive personal, credential, or proprietary data beyond the user's expectations.
The invocation language is broad enough that users may expect the skill to trigger on vague references like prior decisions or memory-related phrases without clear boundaries. In a system that stores conversation history permanently, ambiguous triggers increase the risk of over-collection and unexpected activation, especially when users do not realize what content will be archived or recalled.
No suspicious patterns detected.