T02 · Agent Memory Poisoning
- Location
scripts/auto_created_skill.py:117- Finding
Persistent System-Prompt Injection Through Automatically Generated Skills
- Content
View full analysis
AutoCreatedSkill | None: """ Create a Skill from a completed task. """ if not self.check_should_create(task_completed): return None name = task_completed.get("task", "untitled") context = task_completed.get("context", "") trigger = task_completed.get("trigger_keywords", []) # Generate Skill name safe_name = re.sub(r'[^a-zA-Z0-9_-]', '_', name)[:50] # Generate system prompt prompt = self._generate_prompt(task_completed) # Generate trigger words if not trigger: trigger = self._extract_keywords(name, context) skill = AutoCreatedSkill( name=f"auto-{safe_name}", description=f"Automatically created Skill derived from task: {name}", trigger=trigger, prompt=prompt, tools=task_completed.get("tools_used", []), examples=[], created_from=task_completed.get("task", ""), ) skill.save() return skill def _generate_prompt(self, task: dict) -> str: """Generate the system prompt for the Skill.""" name = task.get("task", "") context = task.get("context", "") return f"""You are skilled at handling the following task: {name} Background: {context[:500]} When encountering a similar task, follow these steps: 1. Understand the task objective 2. Identify the required tools 3. Create an execution plan 4. Execute the plan 5. Verify the result""" ``` The generated prompt is subsequently placed in a system-prompt section and written to the active workspace Skill directory: ```python ## 系统提示词 {self.prompt} ``` ```python def save(self): """Save the Skill under skills/auto_created/.""" path = os.path.join(SKILLS ...[truncated 2840 chars]- Remediation
View remediation
