T01 · Skill Instruction Hijacking
- Location
SKILL.md:29- Finding
Persistent Cross-Agent Instruction and Memory Poisoning
- Content
View full analysis
&limit=5" ### After completing ANY significant work: Write results to shared memory: curl -s -X POST $MEMCLAWZ_URL/api/v1/add \ -H "Content-Type: application/json" \ -d '{"content": "", "agent_id": "$MEMCLAWZ_AGENT_ID", "memory_type": ""}' ``` ``` ### Technical Analysis The skill requires an agent to query a shared memory service before every task and use returned content as operational context. It provides no trust validation, provenance enforcement, content sanitization, or separation between informational memory and executable agent instructions. The instructions also direct users to append this behavior to `AGENTS.md`. That change persists beyond the current skill invocation and causes future sessions to continue retrieving and consuming shared content. An attacker who can submit memories can store instruction-like text designed to alter agent behavior, override task objectives, request sensitive information, or induce unsafe tool calls. Because the same service supports both writing and searching memories, malicious content can propagate between agents. The persistence in `AGENTS.md` expands the issue from a single-s ...[truncated 1482 chars]- Remediation
View remediation
