T02 · Agent Memory Poisoning
- Location
src/index.py:302- Finding
Persistent Agent Memory Poisoning Through Untrusted Context Injection
- Content
View full analysis
Vulnerability Details
File Location:
src/index.py:302-365
Vulnerability Type: Persistent prompt injection through stored memory
Risk Level: HighVulnerable Code
python def kb_context(self, current_input: str, max_length: int = 4000) -> Dict: """为当前对话生成知识库上下文""" # 提取关键词 keywords = self._extract_keywords(current_input) if not keywords: return { "success": True, "context": "", "relevant_entries": 0, "injected": False, "provider": "knowledge-spider" } # 用关键词搜索 all_results = [] for kw in keywords[:2]: results = self._semantic_search(kw, limit=3) all_results.extend(results) # 去重并排序 seen_ids = set() unique_results = [] for r in all_results: if r['id'] not in seen_ids: seen_ids.add(r['id']) unique_results.append(r) unique_results = unique_results[:5] if not unique_results: return { "success": True, "context": "", "relevant_entries": 0, "injected": False, "provider": "knowledge-spider" } context_parts = [ "## 相关知识库 (Relevant Knowledge)", "以下是从历史记忆中提取的相关信息,请优先考虑:", "" ] for i, entry in enumerate(unique_results, 1): date = entry['timestamp'][:10] if entry['timestamp'] else "未知" emoji = { 'preference': '⭐', 'fact': '📖', 'task': '✅', 'important': '🔴', 'general': '📝' }.get(entry['category'], '📝') context_parts.append( f"{i}. {emoji} [{entry['category']}] {date}: {entry['content'][:120]}" ) context_parts.append("") context_parts.append("## 当前对话") context = "\n".join(context_parts) if len(context) > max_length: context = context[:max_length-3] + "..."Technical Analysis
The
memory_storeinterface acc ...[truncated 2127 chars]- Remediation
View remediation
Remediation Suggestions
- Treat every stored record as untrusted data rather than an instruction.
- Remove wording that tells the agent to prioritize retrieved content.
- Place retrieved records inside an explicit data-only boundary and state that instructions within the records must not be followed.
- Detect instruction-like content during storage and retrieval, and either reject it, quarantine it, or require explicit user approval before context injection.
- Preserve provenance, including who stored the record, when it was stored, and whether it has been reviewed.
- Separate trusted administrator-authored memories from ordinary user-authored content.
- Require explicit confirmation before injecting sensitive or instruction-like records into a new session.
- Add tests using payloads such as “ignore previous instructions” and verify that they are represented only as quoted data.
