T02 · Agent Memory Poisoning
- Location
SKILL.md:171- Finding
Uncontrolled Persistent Agent Memory Modification
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 171-176
Vulnerability Type: Persistent memory poisoning through untrusted project retrospectives
Risk Level: HighVulnerable Code
markdown **2. Project-level retrospective (after Phase 5)** - Orion completes the final summary in `DECISION_LOG.md` - Compare the project against the existing lessons and identify new lessons - Append new lessons to the "Collaboration Reflections" section of `MEMORY.md` Retrospective results do not modify this Skill's `SKILL.md`; they are appended to `~/.openclaw/workspace/memory/YYYY-MM-DD.md`.Technical Analysis
The Skill instructs the agent to persist project-derived lessons in a global, cross-session memory directory. These lessons may be derived from project documents, handoff files, research outputs, or other content that is not necessarily trusted.
No mandatory human approval, provenance validation, content sanitization, or project-specific memory isolation is required before the persistent write. Consequently, attacker-controlled project content could be reframed as a retrospective lesson and stored as durable agent guidance.
This differs from ordinary project logging because the destination is the agent's long-term workspace memory rather than a file isolated to the current project. If later sessions automatically read that memory, the injected content can continue influencing the agent after the original project has ended.
Attack Path
- An attacker gains control over, or contributes content to, a project input, research result, handoff document, or deliverable.
- The attacker embeds misleading operational guidance designed to appear to be a reusable project lesson.
- During the Phase 5 retrospective, the agent identifies that content as a new lesson.
- Following the Skill instructions, the agent appends the lesson to
~/.openclaw/workspace/memory/YYYY-MM-DD.md. - Future sessions l ...[truncated 804 chars]
- Remediation
View remediation
Remediation Suggestions
- Store retrospectives inside the current project directory by default, such as
00_pipeline/retrospectives/, rather than in global agent memory. - Require explicit, informed human approval before writing any project-derived content to persistent cross-session memory.
- Present the exact proposed memory entry and destination to the human reviewer before committing it.
- Record provenance metadata, including the source project, source files, author, approval identity, and approval timestamp.
- Reject memory entries containing executable commands, agent-control instructions, permission changes, credential requests, or directives that override system and user policies.
- Separate factual lessons from behavioral instructions. Persistent behavioral rules should require a higher approval threshold.
- Use project-scoped namespaces and expiration periods so project-specific lessons do not automatically affect unrelated work.
- Provide a review and rollback mechanism for newly created memory entries.
- Store retrospectives inside the current project directory by default, such as
