T02 · Agent Memory Poisoning
- Location
SKILL.md:113- Finding
Untrusted Shared-Pool Memories Can Persistently Influence Agent Responses
- Content
View full analysis
` and use returned memories to inform your response. - On session end: call `PATCH /api/v1/memory/sessions/:id` with `ended: true` and a summary. ## Shared Pools - The `POST /api/v1/memory` and `POST /api/v1/memory/sessions` endpoints accept an optional `"poolId"` field. - When `poolId` is provided, the memory or session is shared with all pool members who have memory read access. - The agent must have readwrite access to the pool's memory module to write shared memories. - Search (`GET /api/v1/memory/search`) and list (`GET /api/v1/memory`) results automatically include data from pools the agent belongs to. - Pool data in responses includes `poolId` and `poolName` fields to distinguish shared data from the agent's own data. ``` ### Technical Analysis The skill instructs the agent to use retrieved memories to inform responses. Search and list results automatically include records written to shared pools, but the instructions do not require the agent to: - Treat recalled content as untrusted data. - Distinguish factual data from instructions embedded in memory content. - Validate the author or provenance of shared records. - Restrict recall to private memories when shared data is unnecessary. - Obtain confirmation before acting on sensitive claims originating from a pool. Consequently, a pool member with legitimate write access—or an attacker who compromises such a member—can store instruction-like or misleading conte ...[truncated 1748 chars]- Remediation
View remediation
