T02 · Agent Memory Poisoning
- Location
openclaw_integration.py:70- Finding
Persistent Memory Poisoning Through Untrusted Session Content
- Content
View full analysis
List[MemCell]: """从文本中抽取记忆 - 基于句子分析""" mem_cells = [] timestamp = datetime.now().isoformat() # 分句 sentences = self._split_sentences(text) for sentence in sentences: if not sentence.strip(): continue # 判断句子类型 memory_type = self._classify_sentence(sentence) if memory_type: cell_id = f"mem_{uuid.uuid4().hex[:12]}" mem_cell = MemCell( id=cell_id, content=sentence.strip(), memory_type=memory_type, source=source, created_at=timestamp, updated_at=timestamp, importance=self._calc_importance(sentence, memory_type), tags=[memory_type] ) mem_cells.append(mem_cell) return mem_cells ``` `memory_extraction_v3.py:101-110`: ```python # 偏好型:包含喜欢、偏好、讨厌等 if any(kw in sentence for kw in ['喜欢', '偏好', '讨厌', '习惯']): return MemoryType.PREFERENCE.value # 约束型:包含必须、不能、禁止等 if any(kw in sentence for kw in ['必须', '不能', '禁止', '不要', '务必']): return MemoryType.CONSTRAINT.value ``` `memory_retrieval.py:288-307`: ```python if not resu ...[truncated 2924 chars]- Remediation
View remediation
... ``` 7. Separate declarative user facts from imperative instructions. Stored memories should never be interpreted as system or developer instructions. 8. Add tenant and session isolation so one user's memories cannot affect another user's context. 9. Implement memory review, revocation, expiration, and audit-log controls. 10. Add adversarial tests covering quoted instructions, role spoofing, indirect prompt injection, and cross-session persistence. ]]>
