T02 · Agent Memory Poisoning
- Location
scripts/generate-report.sh:9- Finding
Untrusted Remote Hotspot Content Is Persisted in Agent Memory
- Content
View full analysis
/dev/null else curl -s --max-time 10 "$url" -o "$output" 2>/dev/null fi } ``` Remote hotspot titles are extracted without sanitization or trust metadata. For example, the Weibo source is processed as follows: ```bash fetch_weibo() { log_info "获取微博热搜..." local output="$DATA_DIR/weibo_${DATE}_${TIME}.json" if [[ "$USE_REAL_API" == "true" ]]; then # 尝试真实API(需要代理或特殊处理) local url="https://weibo.com/ajax/side/hotSearch" if fetch_url "$url" "$output.tmp"; then # 解析真实数据 if jq -e '.ok' "$output.tmp" > /dev/null 2>&1; then jq '[.data.realtime[] | {rank: .rank, title: .word, heat: .realpos, tag: .icon_desc}] | {platform: "weibo", date: "'$DATE'", time: "'$TIME'", data: .}' "$output.tmp" > "$output" rm -f "$output.tmp" log_info "微博热搜(真实数据)已保存" return fi fi log_warn "真实API获取失败,使用模拟数据" fi ``` The Douyin integration relies on a third-party aggregation service: ```bash fetch_douyin() { log_info "获取抖音热搜..." local output="$DATA_DIR/douyin_${DATE}_${TIME}.json" if [[ "$USE_REAL_API" == "true" ]]; then # 使用第三方聚合API local url="https://api.oioweb.cn/api/toutiao/douyinHot" if fetch_url "$url" "$output.tmp"; then if jq ...[truncated 5479 chars]- Remediation
View remediation
