T02 · Agent Memory Poisoning
- Location
SKILL.md:198- Finding
Persistent Agent Behavior Modification Through Self-Evolution Instructions
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 198–204
Vulnerability Type: Persistent memory poisoning and self-modification
Risk Level: MediumVulnerable Code
markdown ## Self-Evolution Mechanism After each execution of this Skill: 1. Evaluate whether the output achieved the intended goal: **pass / fail**. 2. If it fails, reflect on the cause of failure and append a “failure case + improvement suggestion” to `diary/YYYY-MM-DD.md`. 3. If a certain improvement suggestion is repeatedly mentioned in the most recent three executions, refine it into a formal rule and submit a PR to modify this `SKILL.md`.Technical Analysis
The skill is declared as a MATLAB paper-reproduction workflow, but this section instructs the agent to create persistent, cross-session records and convert repeated suggestions into formal changes to its own governing instructions.
Paper content and user input are untrusted. A crafted paper or task can repeatedly induce controlled failures and influence the resulting improvement suggestions. Persisting those suggestions in
diary/YYYY-MM-DD.mdcreates an attacker-influenced state channel. Promoting repeated suggestions intoSKILL.mdthrough a pull request can then propagate that influence to future executions.The instruction does not require validation, sanitization, trusted review, provenance tracking, or explicit authorization before retaining suggestions or proposing changes. Although repository permissions and PR approval may limit the final effect, the requested behavior crosses the skill’s legitimate task boundary and creates a memory-poisoning path.
Attack Path
- An attacker supplies a crafted paper or reproduction request that predictably causes the workflow to fail.
- The paper or request is designed to make the agent derive an attacker-selected “improvement suggestion.”
- Under the self-evolution instructions, the agent appends that suggestion to a persistent diary file.
- The ...[truncated 1088 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the self-evolution mechanism from
SKILL.md. - Keep diagnostic observations within the task-specific
reproduction_log.md; do not reuse them automatically across unrelated sessions. - Prohibit automatic modification of skill instructions and automatic creation of branches, commits, or pull requests.
- If process improvements are desired, produce a non-persistent proposal for explicit human review.
- Require maintainers to verify provenance, remove user- or paper-supplied instructions, and assess security implications before incorporating any proposal.
- Apply repository least privilege so normal skill execution cannot modify the skill package or submit pull requests.
- Ensure logs do not contain paper text, secrets, local paths, credentials, personal data, or other sensitive task content.
- Remove the self-evolution mechanism from
