Persistent Context Injection
Medium
- Category
- Memory Poisoning
- Content
- the exact target path; - the exact rule block below; - whether the action will insert, replace an older equivalent block, or do nothing. 7. Obtain explicit approval before editing the persistent instruction file. 8. Preserve all unrelated instructions. Insert the block in the most relevant general-rules section; otherwise append it cleanly. 9. Re-read the file and verify that the block appears exactly once. 10. Report the changed path and explain that the behavior applies only when that AGENTS.md is actually loaded. Recommend verification in a fresh session when possible.
- Confidence
- 90% confidence
- Finding
- This skill is explicitly designed to modify a persistent instruction file (AGENTS.md) so future agent behavior changes beyond the current interaction. Although it requires explicit user approval and includes some safety constraints, it still performs durable context injection, which can be abused to alter agent policy, create hidden persistence, or normalize behavior changes that outlive the initiating request.
