T01 · Skill Instruction Hijacking
- Location
references/openclaw-plugin/plugin.mjs:21- Finding
Persistent memory is injected into agent sessions with system-level authority
- Content
View full analysis
0) { return { injected: response.data.memories.map(m => ({ role: 'system', content: `[agentmemory] Relevant memory: ${m.content}` })), source: 'agentmemory' }; } } catch (err) { ``` ### Technical Analysis The plugin retrieves persistent memory from the agentmemory server and assigns every returned item the `system` role. Memory content is not validated, sanitized, escaped, or separated from executable instructions. A system message generally has greater authority than user-provided content. Consequently, any actor capable of writing, importing, or modifying a memory can persist instructions that alter future agent behavior. Prefixing the content with `[agentmemory] Relevant memory:` does not create a security boundary. The plugin configuration declares a `token_budget`, but this value is not applied when constructing the injected messages. The server can therefore return content beyond the intended budget. This behavior is especially dangerous because the project exposes several write paths, including memory-saving tools, automatic post-session capture, and bulk import. The issue therefore supports persistent memory poisoning as well as instruction hijacking. ### Attack Path 1. An attacker causes crafted content to be stored through `memory_save`, bulk import, automatic capture, or direct access to the memory API. 2. The content inclu ...[truncated 914 chars]- Remediation
View remediation
