T01 · Skill Instruction Hijacking
- Location
plugin/index.js:45- Finding
Untrusted Hot-Memory Content Is Automatically Injected into Agent Prompts
- Content
View full analysis
{ if (!existsSync(HOT_DIR)) return; const now = Date.now(); try { const hotContent = readdirSync(HOT_DIR) .filter((f) => f.endsWith(".md")) .map((name) => ({ name, path: join(HOT_DIR, name), mtime: statSync(join(HOT_DIR, name)).mtimeMs, })) .filter((f) => now - f.mtime < HOT_AGE_MS) .sort((a, b) => b.mtime - a.mtime) .map((f) => { const c = readFileSync(f.path, "utf-8").trim(); if (!c) return null; return `## 热记忆: ${f.name.replace(/\.md$/, "")}\n${c}`; }) .filter(Boolean); if (hotContent.length > 0) { return { prependContext: hotContent }; } } catch { // 静默失败 } }); ``` ### Technical Analysis The `before_prompt_build` hook reads every recent Markdown file from `~/.openclaw/memory_fs/hot` and inserts its contents directly into the agent context through `prependContext`. The implementation does not: - Mark the imported content as untrusted reference data. - Instruct the model not to execute instructions found in memory. - Sanitize or classify stored instructions. - Restrict injection to trusted memory producers. - Enforce a file-size, aggregate-size, or token limit. Consequently, prompt instructions contained in a checkpoint, conversation record, or tool output can be interpreted as authoritative instructions in subsequent prompts. Because this hook runs before prompt construction, the malicious content can continue influencing future interactions while the file remains in the hot tier. The `tokenBudget` and `safetyBuffer` settings declared i ...[truncated 1904 chars]- Remediation
View remediation
