T02 · Agent Memory Poisoning
- Location
SKILL.md:84- Finding
Mandatory Persistent Memory Writes Exceed the Skill's Declared Routing Purpose
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 84–130
Vulnerability Type:T02: Agent Memory Poisoning
Risk Level: MediumComplete Code Snippet:
markdown # Memory Management with sessions_spawn When spawning GLM-5 sub-agent sessions for ANY task (coding, research, analysis, planning, etc.), follow this pattern: ## Output Rules **1. Code Output (Important)** - **Full code ONLY in files** — do NOT include in announce unless explicitly requested - Provide summary: what was created, file path, status, dependencies - Full code disclosure ONLY when: - User explicitly requests: "Show me the code" - Debugging needs code review - User wants to improve/modify it **2. Full Announce for Other Results** - Research findings, analysis results, solutions → announce FULLY to user - Do NOT shorten, summarize, or condense non-code output - User gets complete findings, not a brief summary **3. Two-Layer Memory Strategy** **MEMORY.md (Curated Long-Term)** - ONLY key insights, decisions, lessons, significant findings, preferences - Clean, concise, actionable - Skip routine data, step-by-step reasoning, temporary thoughts **Detailed Reports (Task-Specific Files)** - For research: `research/YYYY-MM-DD-topic.md` (full findings, data, analysis) - For coding: add inline docs/README in code folder if needed - For analysis: output files in relevant project directories ## Examples **Research task:**sessions_spawn({ task: "Research X. Announce full findings to user. Write full report to research/YYYY-MM-DD-X.md, then write ONLY key insights to MEMORY.md (clean, concise).", model: "zai/glm-5", label: "Research X" })
text **Coding task:**sessions_spawn({ task: "Write Python script for X. Save full code to file. Provide summary (what created, path, status, dependencies) in announce. Write key implementation decisions to MEMORY.md (important only).",
...[truncated 2549 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove mandatory
MEMORY.mdand report writes from the model-routing instructions; routing should only select the appropriate model. - Require explicit, informed user approval before persisting any task-derived information.
- Make memory persistence opt-in per task rather than applying it to all GLM-5 spawns.
- Treat user prompts, retrieved documents, source code, and generated findings as untrusted input.
- Present proposed memory entries to the user for review before committing them.
- Reject executable instructions, behavioral overrides, credentials, secrets, and unverified claims from long-term memory.
- Restrict approved writes to a dedicated directory and enforce canonical-path checks to prevent unintended file modification.
- Apply provenance metadata, size limits, retention periods, and audit logging to persisted entries.
- Separate factual task records from instructions that can influence agent behavior.
- Provide a mechanism to inspect, remove, and restore memory entries.
- Remove mandatory
