T02 · Agent Memory Poisoning
- Location
references/project-config.md:15- Finding
Persistent Agent Configuration Poisoning Through Unconditional Always-Load Directives
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This Go helper is mostly coherent, but it directs agents to make persistent future-agent instruction changes without explicit user approval.
Review before installing. The skill can be useful for Go work, but do not let it modify CLAUDE.md, AGENTS.md, GEMINI.md, Cursor rules, or Copilot instructions unless you have seen the exact diff and want future agents to auto-load these Go skills. Prefer a pinned gopls version.
references/project-config.md:15Persistent Agent Configuration Poisoning Through Unconditional Always-Load Directives
SKILL.md:14Mutable Latest Version Used for Executable gopls Dependency
The skill states that the project-layout skill writes an always-load directive automatically at project creation, with no user confirmation needed. This is dangerous because it persistently alters agent instruction files and can force future skill execution across the repository without informed consent, creating a durable prompt-injection and policy-manipulation surface.
The description says the orchestrator is "always active on any Golang coding, review, debug, or setup task," which is broad enough to trigger on incidental or low-risk Go mentions. In a skill-routing system, overly broad activation can cause unintended tool use, extra context loading, and security-relevant side effects when the skill later recommends configuration changes or invokes auxiliary tooling.
The instruction "For every Go task, identify all relevant skills and load them together" is ambiguous and encourages maximal loading without clear boundaries. This increases the chance of unnecessary privilege use, hidden behavior, or accidental activation of skills with write or shell capabilities, especially in mixed-context conversations where "Go task" is not tightly defined.
Configure mode directs the agent to write to project agent-config files but does not prominently warn that this changes persistent instruction surfaces that may affect future agent behavior. Modifying files like CLAUDE.md or AGENTS.md can create durable auto-invocation behavior, so users need explicit notice and consent before those files are changed.
The guidance says any new Go project should get an always-load directive, which broadens activation based on general project state rather than a narrowly scoped user request. In an agent skill, this can cause persistent behavior changes across future sessions and expand the skill’s influence beyond the immediate task, increasing the chance of unnecessary or unintended instruction loading.
The phrase 'without asking the user' explicitly authorizes autonomous modification of project instruction files during project creation. In this context, that is risky because these files are high-leverage control points for downstream agent behavior, so an unapproved change can persistently force skill loading and reduce user control over later interactions.
### When it gets written
- **At project creation** — the `samber/cc-skills-golang@golang-project-layout` skill writes this directive automatically as part of its Initialization Checklist, without asking the user.
- **On demand** — running `/golang-how-to configure` writes it too (if missing), in addition to any `## Required Go skills` block confirmed in Step 3 below.
### Insertion point
The file instructs the agent to modify project configuration files automatically and frames some of those changes as not needing user confirmation. That is dangerous because it normalizes persistent file edits to agent-control surfaces without a clear user-facing warning, which can silently alter future agent behavior and repository policy.
No suspicious patterns detected.