T02 · Agent Memory Poisoning
- Location
SKILL.md:25- Finding
Untrusted Research Content Can Be Written to Persistent Agent Memory
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 25–35
Vulnerability Type: Persistent memory poisoning
Risk Level: MediumVulnerable Instructions
markdown ### When I encounter something I don't know: 1. Add to `memory/gaps.md` with status "TODO" 2. Research (RSS feeds, web search, docs) 3. Attempt to solve 4. On success: mark gap "DONE" + date + notes 5. On failure: keep as TODO, note blockers ### After learning something significant: 1. Add to `memory/YYYY-MM-DD.md` under "## Learned" 2. Store in vector memory: `python3 scripts/ollama_mem.py add "insight" --category learning --importance 0.8` 3. Update `memory/gaps.md` if gap was closed 4. Update `MEMORY.md` if major milestoneTechnical Analysis
The skill instructs the agent to research information from RSS feeds, web search results, and documentation, and then persist learned information in daily logs, vector memory, gap records, and long-term memory. It does not require source validation, provenance metadata, sanitization, separation of quoted content from agent instructions, or user approval before persistent writes.
An attacker who controls or influences a researched source could embed deceptive claims or instruction-like text in that source. If the agent interprets this content as a significant insight and stores it, later memory retrieval may present the hostile content as trusted historical context. The risk is especially relevant to vector memory because semantic retrieval can surface stored content in unrelated future sessions.
The project contains only
SKILL.md; the referencedscripts/ollama_mem.pyimplementation is absent and therefore was not available for verification. Consequently, no claim is made that the storage utility itself executes stored content.Attack Path
- The agent encounters a knowledge gap and follows the instruction to research RSS feeds, websites, or documentation.
- An attacker- ...[truncated 1103 chars]
- Remediation
View remediation
Remediation Suggestions
- Require explicit user approval before information from external sources is added to long-term or vector memory.
- Store provenance metadata with every entry, including the source URL, retrieval date, author or publisher, and a trust classification.
- Keep raw research notes in an isolated, untrusted store rather than directly placing them in operational memory.
- Sanitize stored content by rejecting or quarantining imperative instructions, role directives, tool commands, credential requests, and text that attempts to modify agent policy.
- Require corroboration from multiple trusted sources before promoting research into
MEMORY.mdor assigning it high importance. - Mark retrieved memories as untrusted data and prohibit treating them as system or developer instructions.
- Add review, expiration, correction, and deletion workflows so poisoned entries can be identified and removed.
- Restrict memory-writing utilities to designated files and structured fields, with audit logging for all persistent changes.
