T02 · Agent Memory Poisoning
- Location
SKILL.md:40- Finding
Persistent Memory Poisoning Through User-Controlled Preferences and Phrase Mappings
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:40-44,SKILL.md:73-90, andSKILL.md:92-107
Vulnerability Type:T02: Agent Memory Poisoning
Risk Level: MediumVulnerable Code Snippets
Translated faithfully into English from the source instructions at
SKILL.md:40-44:markdown ## 0. Memory Activation Before performing any task, memory must be activated. 1. Read user preferences: `view_file .agent/memory/user-preferences.md` 2. Apply preferences: Use user preferences by default instead of system defaults.Translated faithfully from
SKILL.md:73-90:markdown User input → Parse keywords → Query cheat-sheet.md │ ┌─────────┴─────────┐ Match No match │ │ Use standard mapping Trigger learning process │ Ask user intent │ Record new mapping Record location: Chapter 6, "User Custom Area," in `examples/cheat-sheet.md`Translated faithfully from
SKILL.md:92-107:markdown ## E. Preference Extractor Actively identify and confirm the user's expression preferences at the end of a conversation. Trigger timing: Proactively ask at the end of every conversation. Output format: Session summary: - Animation preference: [detected preference] - Corner-radius preference: [detected preference] - Spacing preference: [detected preference] Should these preferences be set as defaults? [Yes/No/Partial selection] Record location: `.agent/memory/user-preferences.md`Technical Analysis
The Skill creates a persistent feedback channel between user-controlled conversation content and files consulted during future executions. It requires the Agent to read
.agent/memory/user-preferences.mdbefore every task and apply ...[truncated 2405 chars]- Remediation
View remediation
Remediation Suggestions
- Make persistent memory access opt-in for each task instead of mandatory.
- Store preferences as schema-validated data, such as JSON containing enumerated animation styles and bounded numeric spacing values.
- Reject free-form instructions, tool directives, shell commands, file paths, markup directives, and executable content in persisted values.
- Separate stored data from executable Agent instructions and explicitly state that memory contents are untrusted data.
- Require explicit, informed confirmation before every write and show the exact normalized value and destination.
- Restrict writes to a dedicated Skill-specific data file; do not modify
SKILL.mdor documentation that may be interpreted as instructions. - Apply length limits, character allowlists where appropriate, escaping, and canonicalization before persistence.
- Record provenance, timestamp, requesting user, and a reversible change history for each stored preference.
- Prevent preferences created by one user or workspace context from being applied to another without authorization.
- Add integrity checks and provide a command to inspect, revoke, or reset all remembered values.
- Treat
examples/cheat-sheet.mdas immutable documentation. Store custom mappings in a validated data structure that cannot introduce new Agent instructions.
