T02 · Agent Memory Poisoning
- Location
SKILL.md:56- Finding
Untrusted Conversation Content Can Persistently Influence Future Agent Sessions
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 56, 81, 139–151, and 163
Vulnerability Type: Persistent memory poisoning through automatic storage and recall
Risk Level: MediumComplete Vulnerable Segment
The following is an English translation of the relevant instructions from
SKILL.md:text Line 56: autoRecall=true (automatically search relevant memories at session start), autoCapture=false (automatic capture is disabled by default to avoid noise), captureCategories=["preference","decision","fact"], minImportance=0.7. At session start, relevant historical memories are automatically recalled, and during conversations information is automatically stored according to category and importance. Line 81: Add the memory protocol to AGENTS.md or SOUL.md: At session start, read SESSION-STATE.md to obtain active context, use memory_recall to search relevant history, and inspect memory/YYYY-MM-DD.md for recent activity. When the user provides specific details, write them to SESSION-STATE.md before replying. Store important decisions using memory_store. Store preferences with importance 0.9 and category preference. Lines 139–151: WAL protocol: first write the information into SESSION-STATE.md. Store the database migration decision as an important decision. In a subsequent session, recall the PostgreSQL decision. The Agent automatically follows that decision and no longer recommends MongoDB. Line 163: The recommended configuration is autoRecall=true and autoCapture=false. If automatic capture is enabled, use minImportance=0.8 and restrict captureCategories to ["preference","decision"].Technical Analysis
The Skill establishes a persistent trust path from conversation input to future Agent behavior:
- User-provided details can be written to
SESSION-STATE.mdbefore the Agent responds. - Decisions, preferences, and facts can be copied into long-term files or the vector database.
- Future sessions automatically read or seman ...[truncated 2926 chars]
- User-provided details can be written to
- Remediation
View remediation
Remediation Suggestions
-
Treat recalled memory as untrusted data
- Explicitly prohibit interpreting recalled content as Agent instructions.
- Delimit recalled records from system and developer instructions.
- Require current-session validation before recalled content influences tool calls or security-sensitive decisions.
-
Require explicit storage approval
- Replace the unconditional requirement to write specific details before replying with a confirmation workflow.
- Keep
autoCapturedisabled by default and require informed opt-in before enabling it. - Show the exact proposed record, category, retention period, and scope before storage.
-
Add content filtering
- Reject credentials, API keys, authentication tokens, private keys, and other secrets.
- Reject instruction-like records that attempt to alter Agent policies, tool permissions, or safety constraints.
- Minimize personal and confidential information before creating embeddings or backups.
-
Add provenance and lifecycle metadata
- Record the source, author, creation time, confidence, intended scope, and expiration time for every memory.
- Distinguish user-confirmed facts from inferred or unverified statements.
- Expire stale memories automatically and require reconfirmation of consequential decisions.
-
Introduce trust boundaries
- Isolate memories by user, project, and workspace.
- Do not retrieve one user's or project's records in another context.
- Use allowlisted categories and deny storage of behavioral rules or privileged instructions.
-
Protect persistent storage
- Apply restrictive filesystem permissions to session state, long-term memory, vector databases, exports, and backups.
- Encrypt sensitive records and backups at rest.
- Validate file ownership and integrity before loading memory files.
-
Provide review and deletion controls
- Present recalled records and their provenance to the user.
- Re ...[truncated 450 chars]
-
