T02 · Agent Memory Poisoning
- Location
SKILL.md:66- Finding
Untrusted Conversation Content Can Be Persisted as Long-Term Agent Memory
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a cost-saving guide, but it asks agents to persist user and project memories and use secondary models without enough consent, privacy, or source-trust controls.
Install only if you are comfortable with persistent memory files. Require review and approval of proposed memories, block secrets and sensitive personal data, restrict writes to a dedicated memory directory, choose any secondary model/provider explicitly, and treat stored memories as user-editable notes rather than trusted instructions.
SKILL.md:66Untrusted Conversation Content Can Be Persisted as Long-Term Agent Memory
Referenced artifact was not completely inspected
1. **Copy this skill** into your agent's skill directory (or paste `SKILL.md` into your system prompt).
Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.
version: 1.0.0
author: OpenClaw Community
tags: [optimization, tokens, cost-reduction, context-management, memory]
model: any
---
# Token Optimizer
The skill explicitly instructs agents to extract and persist user-related information such as preferences, expertise, and project context into memory files, but it provides no privacy guardrails, consent requirements, retention limits, or restrictions on sensitive data. In practice this can lead to unnecessary storage of personal or behavioral data across sessions, increasing privacy, compliance, and data leakage risk if memory files are exposed or reused inappropriately.
No suspicious patterns detected.