T02 · Agent Memory Poisoning
- Location
KNOWLEDGE/case-log.md:24- Finding
Unvalidated User Feedback Can Poison Persistent Shared Knowledge
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a Chinese wisdom advisor, but it asks for sensitive personal and business context and instructs agents to persist user feedback into shared knowledge files.
Install only if you are comfortable with a Chinese-language advisory skill that may ask for birth/spatial/resource details and may encourage recording outcomes. Do not provide precise personal identifiers, confidential workplace or business information, or sensitive strategy details. Run it in a read-only environment unless the persistent case-log and mapping update behavior has been removed or placed behind explicit review and consent.
KNOWLEDGE/case-log.md:24Unvalidated User Feedback Can Poison Persistent Shared Knowledge
SKILL.md:31Mandatory Collection and Potential Persistence of Excessive Personal and Business Data
The skill explicitly requires collecting sensitive personal data such as birth time, location/spatial details, and core resources, then using it for metaphysical profiling. This is dangerous because it solicits sensitive information without privacy notice, minimization, consent language, retention limits, or a clear necessity standard, creating avoidable privacy and profiling risk.
The file is entirely written in Chinese and states it defines the structure and depth of 'perfect responses' for the related skill, indicating the examples are intended to shape response behavior. There is no indication that users may choose another language or that the Chinese-only constraint is optional or region-specific.
The disclaimer is written primarily in Chinese and does not provide a language choice or explain a justified China-only audience restriction. Users who cannot read Chinese may miss safety, liability, and proper-use limitations, increasing the chance of misuse or uninformed reliance on the skill's outputs.
The file is written entirely in Chinese and presents the protocol as the default operating specification for the skill, with no indication that users may choose another language or locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.
The file states it defines behavior for apply-china-classics, but the provided manifest is for apply-china-wisdom. This is an active documentation-to-skill identity contradiction, creating uncertainty about whether this protocol belongs to the declared skill.
The file explicitly instructs the AI to persistently update repository knowledge files based on user feedback, creating a self-evolution loop that exceeds a normal advisory or read-only knowledge skill. This is dangerous because it turns untrusted user input into durable instruction changes, enabling prompt injection persistence, knowledge poisoning, and drift in future behavior.
The documented 'evolution protocol' grants the agent ongoing authority to modify stored mappings and indexes, which is not obviously required for a wisdom-application skill whose stated purpose is giving cultural guidance. Persistent self-modification broadens the attack surface by allowing adversarial feedback to reshape future outputs and potentially embed unsafe instructions into trusted internal files.
The markdown tells the AI to write to repository files whenever users provide feedback, but does not warn users that their input may alter stored knowledge. This is dangerous because users may unknowingly trigger persistent modifications, and attackers can intentionally plant poisoned content that affects later sessions or downstream consumers of the repository.
The file explicitly states it is intended for apply-china-classics while the manifested skill is apply-china-wisdom, indicating cross-skill knowledge leakage or packaging drift. This can cause the agent to load behavior, assumptions, or routing logic not reviewed for the active skill, leading to unintended outputs and weakened security boundaries.
Mandating Chinese-language operation without user choice can bypass user expectations, consent, or platform language controls, increasing the chance of misunderstanding safety-critical guidance. In this skill, which provides interpretive advice, forced language behavior may obscure limitations and reduce user comprehension of risk-related content.
This markdown file contains all user-facing instructions and prompts in Chinese, effectively forcing a specific language for interaction. The policy allows locale constraints only when they are optional or clearly documented as justified, which is not stated here.
This markdown file presents all operational content in a single language and does not indicate that users may choose another language or that the skill is intentionally restricted to a Chinese-speaking context. That creates a natural-language policy concern under the language/locale rule because the skill effectively forces one locale without opt-in.
The file translates classical stratagems into concrete modern workplace and business tactics centered on concealment, manipulation, induced overconfidence, asset transfer, and asymmetric pressure. In this skill context, the content is not merely descriptive or historical; it is structured as an execution-oriented mapping library, which increases the likelihood of harmful real-world misuse in workplace coercion, deceptive competition, or evasion of accountability.
The file provides actionable guidance for information control, power rebalancing, and indirect competitive attacks without sufficient justification tied to a safe business or educational purpose. Because the skill is presented as modern executable advice, these patterns can enable manipulative conduct against colleagues, counterparties, or competitors under the guise of cultural wisdom.
The file is written predominantly in Chinese and describes operational behavior such as the trigger and decoding workflow in Chinese, without stating that users may interact in other languages or choose a locale. Under the language/locale policy rule, this can be a natural-language policy concern when no opt-in or justification is provided.
The README states that all outputs must follow a fixed 'classical minimalist' formatting style, without indicating that users can choose a different language or presentation format. This can reduce usability, obscure safety-critical information for users who need plain or different-language output, and create avoidable misunderstandings in high-stakes advice contexts.
The trigger for Deep Analysis Mode covers very broad categories like life difficulties, confusion, management issues, or philosophical questions, which can match many ordinary user requests unintentionally. This increases the chance that the skill activates high-risk workflows, including sensitive data collection and speculative metaphysical analysis, without clear user consent or expectation.
The Creative Asset Layer is triggered by generic requests to create, continue writing, generate prompts, or build worldviews, which are common tasks and may cause the skill to overtake unrelated conversations. While less severe than data-handling issues, ambiguous activation can still lead to unintended behavior and loss of user control over response mode.
The Tactical Execution Layer is triggered by broad business, workplace, and resource-competition scenarios, then directs the system to apply stratagems and psychological effects. In context, this is more dangerous because it can normalize manipulative or adversarial advice in ordinary professional situations, even though it mentions ethics checks.
The skill mandates a specific classical minimalist output format and presentation style for all outputs, without offering user choice or opt-out. This is primarily a user-control and transparency issue: it can override user preferences and obscure whether the content is adapted to the user's needs versus the skill author's preferred aesthetic.
The simulation mode activates on vague future-prediction or path-forecasting requests and claims to produce probability-weighted outcomes through multi-agent simulation. This can mislead users into attributing unwarranted authority to speculative forecasts, especially in sensitive life or business decisions, without clear limits or disclaimers.
This markdown file is entirely written as a Chinese knowledge index and describes itself as the retrieval base for a skill, but it provides no indication that users may choose another language or opt in to Chinese-only behavior. Because the policy category applies to natural-language content in all file types, this is a language/locale constraint that is not explicitly optional or justified in the file itself.
All user-facing instructional content in this file is in Chinese, and the protocol uses mandatory language such as "AI 必须执行以下流程" without indicating that the user can choose another language. Under SQP-3, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale restriction is clearly documented and justified.
The mode includes users who want to learn how to think or improve cognition, which are broad intents common across many assistants. Although one quoted phrase is specific, the surrounding criteria still lack clear boundaries and exclusion cases.
No suspicious patterns detected.