T02 · Agent Memory Poisoning
- Location
references/agents.md:41- Finding
Automatic Persistent Memory Writes Allow Cross-Session Agent Memory Poisoning
- Content
View full analysis
Vulnerability Details
File Locations:
references/agents.md:41-80references/soul.md:590-618references/soul.md:821-824
Vulnerability Type: Persistent behavioral-state mutation and automatic retention of project analysis
Risk Level: MediumVulnerable Instructions
references/agents.md:41-80:text For compounding quality, read `~/self-improving/memory.md` before non-trivial work, then load only the smallest relevant domain or project files. Before any non-trivial task: - Read `~/self-improving/memory.md` - List available files first: Get-ChildItem -Path '$env:USERPROFILE\self-improving\domains', '$env:USERPROFILE\self-improving\projects' -Filter *.md - Read up to 3 matching files from `~/self-improving/domains/` - If a project is Clearly active, also read `~/self-improving/projects/<project>.md` - "Mental notes" don't survive session restarts. Files do. - Explicit user correction → append to `~/self-improving/corrections.md` immediately - Reusable global rule or preference → append to `~/self-improving/memory.md` - Domain-specific lesson → append to `~/self-improving/domains/<domain>.md` - Project-only override → append to `~/self-improving/projects/<project>.md` - After a correction or strong reusable lesson, write it before the final responsereferences/soul.md:590-618directs the agent to automatically save every completed project analysis tomemory/project-name-YYYYMMDD.md. The stored record includes the project name, analysis date, investment type, scores, investment conclusion, core rationale, risks, deal-killer findings, and data sources. It also instructs subsequent sessions to search these records and compare them with new analyses.references/soul.md:821-824:text Before non-trivial work, load `~/self-improving/memory.md` and only the smallest relevant domain or project files. After corrections, failed attempts, or reusable l ...[truncated 3482 chars]- Remediation
View remediation
Remediation Suggestions
-
Require explicit consent for every persistent write
- Show the exact proposed entry, destination file, scope, and retention period.
- Perform the write only after the user explicitly confirms it.
- Do not interpret ordinary corrections as authorization to create persistent rules.
-
Disable automatic global-rule creation
- Keep corrections scoped to the current conversation by default.
- Require a separate privileged workflow to create global behavioral rules.
- Prevent self-inferred lessons from becoming persistent instructions without human review.
-
Treat stored memory as untrusted data
- Load memory as reference material, not as authoritative instructions.
- Prevent stored entries from overriding system policies, current user instructions, safety controls, or tool authorization requirements.
- Validate entries against a strict schema and reject commands, tool directives, or policy-like instructions.
-
Isolate memory by user and project
- Use separate storage namespaces and access controls for every user and project.
- Do not expose one user's corrections or investment history to another user.
- Apply least-privilege filesystem permissions to all memory files.
-
Minimize confidential retention
- Do not automatically save completed investment analyses.
- Obtain informed consent before retaining project names, conclusions, risks, scores, or source lists.
- Redact sensitive information and support configurable expiration and secure deletion.
-
Add provenance and integrity controls
- Record who created each entry, when it was approved, its intended scope, and its expiration date.
- Provide an auditable review interface and a mechanism to revoke poisoned or obsolete entries.
- Consider signing approved policy entries or separating them from user-authored notes.
-
Constrain subsequent retrieval
...[truncated 267 chars]
-
