T02 · Agent Memory Poisoning
- Location
src/memory/heartflow-memory.js:242- Finding
Persistent System-Prompt Injection Through Raw User Memory
- Content
View full analysis
5) { this.learn(`conversation:${uid}`, input, ['conversation', 'user_input']); } // 2. Detected emotion/pain → store in LEARNED const pain = this._extractPain(judgment); if (pain) { this.learn(`pain:${uid}`, `User emotional signal: ${pain}`, ['emotion', 'pain']); } // 3. Determined scenario → store in EPHEMERAL const what = judgment.whatIsThis; if (what) { this.remember(`context:now`, { whatIsThis: typeof what === 'object' ? (what.scenario || what.category || 'unknown') : 'unknown', shouldRespond: judgment.shouldRespond, }, 3600000); } // 4. Important technical operation → store in LEARNED if (input.includes('修') || input.includes('改') || input.includes('升级') || input.includes('优化')) { this.learn(`tech:${uid}`, input, ['tech', 'operation']); } ``` `scripts/heartflow-memory-inject.js:78-95`: ```javascript if (techOps.length > 0) { lines.push(''); lines.push('【技术操作记录】'); for (const e of techOps.slice(0, 10)) { const ts = e.lastAccessed ? new Date(e.lastAccessed).toLocaleDateString('zh-CN') : '?'; lines.push(` • (${ts}) ${e.value}`); } } lines.push(''); const output = lines.join('\n'); // Output to stdout for use by AGENTS.md / Hermes process.stdout.write(output); ``` `plugins/heartflow-memory-inject.py:142-164`: ```python inject_text = _run_inject() if not inject_text: return {} # Filter sensitive memories inject_text = _filter_sensitive(inject_text) if input_type == "greeting": inject_text = "" if inject_text: boundary_note = ( "\n[Memory notice: the followin ...[truncated 2996 chars]- Remediation
View remediation
