T02 · Agent Memory Poisoning
- Location
scripts/pre-compact.sh:70- Finding
Persistent Prompt Injection Through Unsanitized Resume State
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is purpose-aligned but needs Review because it automatically stores, reloads, and injects session and project memory content without enough scoping or sanitization.
Review the scripts before installing. Use this only in projects where saving full session transcripts and reloading prior context is acceptable, keep thinking/session-logs and .claude/session-resume-card.md out of version control, avoid secrets in chats or memory files, and prefer a pinned or manual install. Consider narrowing the hook matchers and adding sanitization or confirmation before restored text is treated as context.
scripts/pre-compact.sh:70Persistent Prompt Injection Through Unsanitized Resume State
scripts/session-start.sh:26Undocumented Injection of Persistent Agent Memory into Session Context
SKILL.md:27Mutable Unpinned Package Executed During Installation
A description-behavior mismatch is especially dangerous in a hook-based skill because users may grant trust based on the stated purpose while the actual code performs broader repository enumeration and reads memory-like files. Hidden collection of git history, project structure, or local notes can expose sensitive data and indicates deceptive packaging.
Referenced artifact was not completely inspected
Or manually: copy `scripts/pre-compact.sh` and `scripts/session-start.sh` into your project's `.claude/scripts/`, then register the hooks in `.claude/settings.j
Referenced artifact was not completely inspected
Or manually: copy `scripts/pre-compact.sh` and `scripts/session-start.sh` into your project's `.claude/scripts/`, then register the hooks in `.claude/settings.j
Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.
mkdir -p "$BACKUP_DIR"
TIMESTAMP=$(date +%Y%m%d_%H%M%S)
cp "$TRANSCRIPT_PATH" "$BACKUP_DIR/session_${TRIGGER}_${TIMESTAMP}.jsonl"
ls -t "$BACKUP_DIR"/session_*.jsonl 2>/dev/null | tail -n +31 | xargs rm -f 2>/dev/null || true
fi
# --- Resume Card: estado operativo real ---
Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.
# Next step
echo "### Next step"
if [ -f "${PROJECT_DIR}/.claude/current-task.md" ]; then
head -n 3 "${PROJECT_DIR}/.claude/current-task.md"
else
echo "Continuar última acción del assistant"
fi
The script reads and prints a file from the agent configuration directory (.claude/session-resume-card.md) directly into session context. Accessing .claude is sensitive because it can expose internal agent state, prior instructions, secrets, or attacker-planted prompt content that will be injected into the next session; in this skill, that behavior is the core feature, which makes the risk real rather than incidental.
# Resume Card: inyectar estado pre-compaction si existe
if [ -f .claude/session-resume-card.md ]; then
echo "### Resume Card (estado pre-compaction)"
cat .claude/session-resume-card.md
echo ""
fi
The skill describes file-reading behavior and hook-driven script execution but does not declare any explicit tool scope or permissions boundaries. That makes the effective access surface unclear to users and reviewers, increasing the chance that a hook can read sensitive local files without informed consent.
Using npx clawhub@latest install pulls and executes the latest published package version at install time, which is a supply-chain risk because the resolved code can change without review. If the package or one of its dependencies is compromised, users may execute attacker-controlled code during installation.
Registering both hooks with empty matchers causes them to run broadly across sessions and contexts, which increases the blast radius of any unsafe behavior in the scripts. In this skill, that means transcript parsing, file reads, and resume-card injection may occur when not needed, potentially exposing unrelated project or session data.
Both hooks use an empty matcher, which causes the commands to run for all matching lifecycle events without any scoping or restriction. In this skill, that means shell scripts execute automatically at every PreCompact and SessionStart, increasing the chance of unintended execution, surprise persistence, or abuse if the scripts are modified or the skill is installed in an untrusted repository.
The script copies the full session transcript into a persistent project-local backup directory without any consent, minimization, or visibility controls. Because transcripts can contain sensitive prompts, code, secrets, or internal discussion, this increases data retention and exposure beyond the original runtime context.
Backing up entire conversation transcripts into plain files creates persistent copies of potentially sensitive prompts, responses, and embedded secrets. In a project directory context, those files may be read by other tools, synced, committed, or exposed through weaker filesystem controls.
The script extracts recent user and assistant content from the transcript and writes it into a persistent markdown resume card. This republishes conversational content into another file, broadening access and retention surface for potentially sensitive data.
Multiple output strings such as 'Proyecto activo', 'Cambios en curso', and 'Continuar última acción del assistant' are hard-coded in Spanish. This imposes a locale on users without any documented opt-in or language selection mechanism.
The script removes older backup files beyond the most recent 30 using rm -f, which is a destructive operation. Although this cleanup may be intentional, the script provides no user-facing notice or confirmation that retained backups will be deleted.
No suspicious patterns detected.