T02 · Agent Memory Poisoning
- Location
SKILL.md:157- Finding
Untrusted conversational signals can poison persistent decision memory
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This decision-support skill is not clearly malicious, but it automatically stores personal decision patterns and has inconsistent claims about local-only use versus API, callback, and command-execution capabilities.
Review this skill before installing. It may save your decision history and preferences under ~/decision-making and reuse them later, including in personal or business contexts. Install only if you are comfortable with that persistence, can inspect and delete the files, and can restrict network/API/callback use and command execution in your agent environment.
SKILL.md:157Untrusted conversational signals can poison persistent decision memory
SKILL.md:16General command-execution permission exceeds the Skill's legitimate requirements
The manifest presents the skill as local-only and requiring no credentials, while the body later describes external API integration and API key configuration. This creates a trust-boundary mismatch: operators may enable the skill believing it cannot exfiltrate data or use networked services when the documentation elsewhere suggests it can.
The skill repeatedly claims it is local-only and does not access external systems, but later documents API keys, API usage, callback URLs, and network/API failure handling. This inconsistency can mislead users and downstream agents about data flow boundaries, causing sensitive decision-history or preference data to be sent externally under false assumptions.
The skill is explicitly designed to persist and reuse user preferences and decision history across sessions. That creates a real natural-language data retention risk: accumulated behavioral information may be surfaced later, mishandled, or accessed by other local users/processes if storage is not carefully controlled.
The skill advertises read/write/exec capability and describes persistent memory files, but the introduction does not prominently warn users that it will create and modify files under ~/decision-making/. Users may provide personal information without realizing it will be retained across sessions on disk.
The documented callback_url parameter introduces potential outbound transmission, yet no privacy warning explains what data may be sent, when callbacks occur, or how to constrain destinations. In a skill that stores and processes personal decision history, silent callback support materially increases data exfiltration risk.
The instructions tell the agent to automatically record user statements into memory and decision logs, effectively turning ordinary conversation into ongoing personal data collection. Automatic capture raises privacy risk because users may not realize which statements are being stored or how long they will remain available for later reuse.
Prompting the agent to proactively reference historical preferences back to the user increases the chance that retained private behavioral data will be disclosed in contexts where the user did not expect it. This is especially risky in shared screens, logs, demos, or multi-user environments where old personal patterns may be revealed inadvertently.
The example normalizes quoting stored historical patterns from memory files back into responses, reinforcing a workflow that exposes retained personal data as standard behavior. This increases the likelihood of over-disclosure of behavioral preferences and past decisions in future conversations or logs.
The document claims it does not store personal sensitive information, but the core design persists user preferences, personal-life decision patterns, reversals, and decision history to local files. Even if not labeled as 'sensitive,' this behavioral history can become sensitive personal data and create privacy and disclosure risks.
The display name, summary, description, and nearly all user-facing instructions are written only in Chinese, with no indication that users may choose another language. This can constitute a language/locale policy issue when the skill effectively defaults to a single language without opt-in or an explicit documented constraint.
No suspicious patterns detected.