T02 · Agent Memory Poisoning
- Location
SKILL.md:87- Finding
Predictable Temporary Files Can Poison Persistent Agent Memory
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 87-94 and 217-220
Vulnerability Type: Predictable temporary-file use followed by an unsafe persistent-memory append
Risk Level: MediumComplete Code Snippet
bash node scripts/memory-compress.js memory/2026-07-18.md # Specify an output file node scripts/memory-compress.js memory/2026-07-18.md /tmp/compressed.md # Append the compressed output to curated memory node scripts/memory-compress.js memory/2026-07-18.md /tmp/today.md cat /tmp/today.md >> MEMORY.mdmarkdown ## Memory maintenance (every 2-3 days) 1. Run: node scripts/memory-compress.js memory/YYYY-MM-DD.md /tmp/compressed.md 2. Review the compressed result for accuracy 3. Append: cat /tmp/compressed.md >> MEMORY.md 4. Record the maintenance time: date +%s > .last-memory-maintenanceTechnical Analysis
The documented workflow uses fixed names in the shared
/tmpdirectory and later appends their contents to persistent Agent memory. Predictable shared temporary paths are vulnerable to pre-creation, stale-file reuse, symlink manipulation, and time-of-check/time-of-use replacement by another local principal able to write to/tmp.The first example performs the append as a separate command rather than conditionally executing it only after successful compression. If the compressor fails, an existing
/tmp/today.mdmay still be appended. Although the maintenance workflow requests human review, it does not prescribe file ownership, type, permissions, or integrity checks and does not prevent replacement between review and append.The compressor implementation referenced by these instructions is absent from the audited package, so its handling of existing files and symbolic links cannot be verified. The finding is therefore based on the unsafe workflow explicitly prescribed by
SKILL.md, not on unobserved script behavior.Attack Path
- An attacker with access to the same host and shared
/tmpdirectory cr ...[truncated 1260 chars]
- An attacker with access to the same host and shared
- Remediation
View remediation
Remediation Suggestions
- Create a private temporary directory with restrictive permissions:
bash tmpdir="$(mktemp -d)" || exit 1 chmod 700 "$tmpdir" trap 'rm -rf -- "$tmpdir"' EXIT output="$tmpdir/compressed.md"- Append only if compression succeeds:
bash node scripts/memory-compress.js memory/2026-07-18.md "$output" && cat -- "$output" >> MEMORY.md- Before appending, verify that the output is a regular file, is not a symbolic link, is owned by the current user, and has restrictive permissions.
- Keep validation and append in one trusted process where possible to reduce replacement races.
- Display and explicitly approve a diff before modifying persistent memory.
- Parse generated summaries as untrusted data. Do not treat instructions embedded in source logs or summaries as Agent directives.
- Prefer an atomic update: construct a validated replacement file in the same directory as
MEMORY.md, synchronize it, and rename it into place. - Bundle and audit the referenced
scripts/memory-compress.jsimplementation, including its existing-file, symbolic-link, path-validation, and error-handling behavior.
