T02 · Agent Memory Poisoning
- Location
SKILL.md:20- Finding
Untrusted ArXiv Metadata Is Mandatorily Written to Persistent Agent Memory
- Content
View full analysis
"` to get the XML results. 2. Parse the XML (look for ``, ``, `<summary>`, and `<link title="pdf">`). 3. Present the findings to the user. 4. **MANDATORY**: Append the title, authors, date, and summary of any paper discussed to `memory/RESEARCH_LOG.md`. Use the format: ```markdown ### [YYYY-MM-DD] TITLE_OF_PAPER - **Authors**: Author List - **Link**: ArXiv Link - **Summary**: Brief summary of the paper and its relevance. ``` ``` The capability is also described at line 10: ```markdown - **Save to Memory**: Automatically record summarized papers to `memory/RESEARCH_LOG.md` for long-term tracking. ``` ### Technical Analysis The workflow requires the agent to persist titles, author names, links, and summaries derived from remotely supplied ArXiv XML. These fields are untrusted external content. The instructions do not require validation, escaping, provenance labeling, instruction-content filtering, or user authorization before writing the data to long-term memory. An attacker able to publish or influence metadata for a paper could place prompt-like instructions in its title, author data, or abstract. When a matching paper is discussed, the agent is explicitly required to copy or summarize that content into `memory/RESEARCH_LOG.md`. If this log is later loaded into an agent context, the stored text could be mistaken for trusted instructions rather than treated exclusively as quoted research data. The issue does not itself prove that arbitrary commands will be executed. Successful behavioral influence depends on whether and how the surrounding agent system loads the research log in future sessions. Nevertheless, the mandatory, unfiltered persistence creates the prerequisite f ...[truncated 1320 chars]- Remediation
View remediation
