T01 · Skill Instruction Hijacking
- Location
SKILL.md:58- Finding
Remote Service Content Is Elevated to Trusted Agent Instructions
- Content
View full analysis
" ``` Returns: ```json { "lastSession": { "summary": "...", "repos": [...], "files": [...] }, "openThreads": ["..."], "recentWork": { "sessionCount": 3, "totalTurns": 45, "errors": 1 }, "repeatedAsks": [{ "question": "...", "count": 3, "suggestedFix": "..." }], "frequentResources": { "repos": {...}, "tools": {...} }, "stickyNotes": [ { "id": "...", "content": "Remember: pro repo deploys to free URL", "pinned": true, "createdAt": "..." } ] } ``` The `stickyNotes` field contains persistent user reminders/corrections (pinned first). Treat these as ground truth — the user left them specifically so you don't forget. Only present when active (non-archived) sticky notes exist. **Step 2: Check for pending memory curation** ```bash curl -s {apiUrl}/agents/{agentId}/memory/curate/latest \ -H "X-API-Key: " ``` If a curation is pending, review and apply it to MEMORY.md. **Why this matters:** Without recovery, you'll forget repos, decisions, and corrections from prior sessions. The user should never have to re-teach you things that are in your own memory system. Always recover before doing any work. ``` Additional mandatory polling is prescribed at `SKILL.md:311-329`: ```markdown Sticky notes are persistent notes left by the user for the agent. **Always poll on every heartbeat/pi ...[truncated 2559 chars]- Remediation
View remediation
