T02 · Agent Memory Poisoning
- Location
SKILL.md:23- Finding
Untrusted learning content can be promoted into persistent agent-control files
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed self-improvement logger, but it encourages broad persistent agent-memory changes and always-on hooks without enough consent, sanitization, or scoping.
Install only if you want persistent self-improvement logs and agent-memory promotion. Keep logs local, redact secrets and private user data, avoid global hooks unless necessary, review diffs before editing CLAUDE.md/AGENTS.md/SOUL.md/TOOLS.md, and do not promote untrusted user text into future agent instructions.
SKILL.md:23Untrusted learning content can be promoted into persistent agent-control files
hooks/openclaw/handler.js:8Opt-in hooks inject persistent behavioral directives into agent context
The skill is presented primarily as a learning/error logging aid, but it also instructs the agent to extract learnings into reusable skills and run helper scripts that create new skill directories and files from command-line arguments. That capability expansion is not inherently malicious, but it widens the write surface and can cause an agent or user to approve filesystem-modifying behavior they did not expect from the declared purpose.
Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.
Add to ~/.claude/settings.json for global activation:
{
Instructions found that direct the agent to transmit conversation context or user data to external services.
Send message to another session:
sessions_send(sessionKey="session-id", message="Learning: API requires X-Custom-Header")
The activation guidance is very broad and includes common conversational situations such as corrections, missing capabilities, and major tasks. In practice this can cause the skill to trigger in many ordinary interactions and normalize persistent logging or promotion of content into memory files without sufficiently specific scope limits.
The skill instructs creation of a persistent workspace directory under the user's home path for storing learning files. This creates session persistence outside the immediate project scope, which can retain sensitive operational history across tasks and increase the chance of unintended reuse, disclosure, or inclusion in backups and synced storage.
└── FEATURE_REQUESTS.md
### Create Learning Files
```bash
mkdir -p ~/.openclaw/workspace/.learnings
The skill recommends inter-session tools to read transcripts and send learnings between sessions, which creates a clear path for durable retention and redistribution of user-provided context. Even if intended for productivity, this broadens access to potentially sensitive information beyond the original session boundary.
The logging templates explicitly call for storing full context, inputs, parameters, environment details, and user context in durable markdown files. This is dangerous because secrets, PII, internal URLs, tokens, prompts, and proprietary data can be copied into plaintext records that persist and may later be searched, shared, or committed.
The promotion workflow encourages moving learnings into persistent memory and instruction files such as CLAUDE.md, AGENTS.md, TOOLS.md, and workspace guidance. If the original learning contains sensitive or context-bound material, promotion amplifies the leak by spreading it into files that are more likely to be loaded automatically in future sessions.
The trigger phrases are generic everyday language like 'Can you also...' or 'Actually...' and are treated as signals to log durable records. Without exclusions or sensitivity checks, normal chat content can be transformed into persistent artifacts, increasing privacy risk and causing overcollection.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
When the above learning is extracted as a skill, it becomes:
File: skills/docker-m1-fixes/SKILL.md
---
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
Create .claude/settings.json in your project root:
{
The empty matcher causes the hook to run on every user prompt, creating an always-on trigger surface rather than a narrowly scoped reminder. In a self-improvement skill, that broad activation increases the chance of unnecessary context injection, prompt pollution, and abuse if the hooked script is changed or replaced.
The user-level configuration instructs operators to install a globally active hook in ~/.claude/settings.json, which extends the behavior across all sessions and repositories without clear scope boundaries. That persistence magnifies the blast radius of any mistake, noisy behavior, or future script compromise.
The Codex example also uses an empty matcher, so the hook will trigger for every prompt with no filtering. As with the Claude setup, that creates unnecessary always-on behavior and expands the opportunity for context injection or misuse of the configured command path.
The document explicitly describes workspace-based prompt injection, injected context from local files, and cross-session hooks/transcript access, but provides no warning about sensitive data exposure or trust boundaries. In a system that reads workspace files into model context and allows session-history access, users may inadvertently place secrets, personal data, or untrusted instructions where they can influence agent behavior or be disclosed across sessions.
The guide instructs users to create persistent .learnings/ storage in the workspace or skill directory for continuous improvement without discussing retention, review, or sensitivity controls. Because this skill is specifically designed to capture errors, corrections, and operational details, the persisted notes may accumulate prompts, tool outputs, internal paths, credentials, or other sensitive project information over time.
openclaw hooks enable self-improvement
### 3. Create Learning Files
Create the `.learnings/` directory in your workspace:
The file header and usage text state that this helper 'Creates a new skill from a learning entry,' and the implementation writes a new skill directory and SKILL.md template. That behavior is not reflected in the manifest description, which frames the skill as capturing learnings, errors, and corrections for continuous improvement.
The manifest describes a skill focused on recording and reviewing learnings for continuous improvement. This script goes beyond capture/review by generating new skill directories and templated SKILL.md files, effectively authoring new capabilities rather than merely storing or surfacing learnings.
This markdown file includes shell commands such as cp -r ... ~/.openclaw/... and mkdir -p ... that create or modify directories in the user's local environment. The guide presents them as setup steps but does not include any user-facing warning about filesystem changes or their impact.
No suspicious patterns detected.