T02 · Agent Memory Poisoning
- Location
SKILL.md:48- Finding
Untrusted skill metadata can poison persistent Agent routing configuration
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:48-53,SKILL.md:55-58, andSKILL.md:119-131
Vulnerability Type: Persistent routing manipulation through untrusted skill metadata
Risk Level: MediumVulnerable Code Snippets
SKILL.md:48-53:markdown For each `SKILL.md` found, read the YAML frontmatter block (lines between the opening and closing `---`). Extract: - `name` — the skill identifier - `description` — the full triggering description Do not read the body of each SKILL.md; frontmatter only.SKILL.md:55-58:markdown If a skill is missing a `name` or `description` field, skip it and note it in the final report as: `skill-x: skipped — missing description`. Do not fabricate a description. ### Step 3 — Read AGENTS.md Read `AGENTS.md` in the current workspace. Look for it at `./AGENTS.md` relative to the workspace root, or at `~/.openclaw/workspace/AGENTS.md` if no workspace context is set. Identify any existing `## Skill Routing` section. If it exists, it will be fully replaced in Step 6.SKILL.md:119-131:markdown ### Step 6 — Write output **Option A — Append to AGENTS.md (recommended):** Add a `## Skill Routing` section at the end of `AGENTS.md` containing the full `skill_routing:` YAML block inside a fenced code block. If a `## Skill Routing` section already exists, replace it in full — all triggers are regenerated from current descriptions. Any manual edits to the previous section will be lost; users should preserve custom triggers outside this block (see the warning comment in Step 5). **Option B — Standalone file:** Write the YAML block to `router.yml` in the workspace root. Inform the user to reference it in `AGENTS.md` if they want OpenClaw to pick it up automatically.Technical Analysis
The skill instructs the Agent to consume the
nameanddescriptionfields from every installed skill and use that information to generate routing ...[truncated 2993 chars]- Remediation
View remediation
Remediation Suggestions
- Parse YAML frontmatter with a deterministic YAML parser rather than allowing the Agent to interpret raw
SKILL.mdcontent. - Pass only parsed scalar values for
nameanddescriptioninto the routing generator. Explicitly state that these fields are untrusted data and that directives contained within them must never be followed. - Validate each skill name against the exact set of discovered installation directories. Reject names containing control characters, line breaks, YAML metacharacters, or unexpected Unicode characters.
- Enforce a reasonable description length and reject multiline descriptions containing instruction-like constructs, fenced code blocks, role markers, or attempts to address the Agent.
- Serialize output through a safe YAML library so attacker-controlled values cannot create additional keys, rules, comments, or document boundaries.
- Generate triggers using a constrained transformation that outputs only short lowercase phrases matching an allowlisted character set.
- Present the proposed routing configuration and a diff of changes before writing. Require explicit user confirmation before replacing an existing
## Skill Routingsection. - Preserve a backup of the prior routing section and write updates atomically to reduce the consequences of manipulation or generation errors.
- Flag unusually broad triggers and require manual approval when a rule overlaps many unrelated skills or intents.
- Document that installing a third-party skill establishes a trust boundary and recommend reviewing its frontmatter before running the router.
- Parse YAML frontmatter with a deterministic YAML parser rather than allowing the Agent to interpret raw
