T02 · Agent Memory Poisoning
- Location
evolve.sh:20- Finding
Unsanitized Attacker-Controlled Content Is Written to Persistent Agent Memory
- Content
View full analysis
Vulnerability Details
File Location:
evolve.sh, lines 20-40
Vulnerability Type: Persistent agent memory poisoning
Risk Level: MediumVulnerable Code
bash record_experience() { local task_id="$1" local task="$2" local result="$3" local audit_score="$4" local exp_file="${EVOLUTION_DIR}/experience-$(date +%Y-%m-%d).md" log "📚 记录经验:$task_id" cat >> "$exp_file" << EOF --- ## $(date "+%H:%M:%S") - $task_id **任务**: $task **结果**: $result **审计评分**: $audit_score/100 EOFTechnical Analysis
The
record_experiencefunction accepts task identifiers, task descriptions, and execution results from command-line arguments and writes them verbatim into a persistent Markdown file under/root/.openclaw/workspace/memory/evolution.No trust metadata, structural encoding, content filtering, provenance tracking, or separation between untrusted task data and trusted agent instructions is applied. Consequently, an attacker who can influence the task description or result can insert instruction-like Markdown into the persistent experience record.
The shell here-document does not directly execute command substitutions contained inside variable values, so this is not shell command injection. The risk arises when a later agent session or automated workflow reads the generated Markdown as trusted memory or guidance. At that point, embedded instructions could be interpreted as agent directives rather than untrusted historical data.
Attack Path
- An attacker supplies or influences a task description or execution result containing adversarial instructions, such as directions to ignore security constraints, disclose data, or invoke tools.
- The caller passes that content to
evolve.shas the second or third argument. record_experienceappends the content without sanitization or provenance labels to a daily file in the shared agent memory directory.- The malicious content remains present across subse ...[truncated 1003 chars]
- Remediation
View remediation
Remediation Suggestions
- Store task descriptions and results as structured data, such as JSON, rather than instruction-like Markdown.
- Mark every externally supplied field with explicit provenance and trust metadata, for example:
source: externaltrusted: falsecontent_type: task_data
- Ensure memory consumers treat stored content exclusively as quoted data and never as executable instructions.
- Apply length limits and schema validation to task identifiers, task descriptions, and result fields before persistence.
- Escape or encode Markdown control characters and delimit untrusted content clearly when a human-readable Markdown representation is required.
- Store records in a skill-owned directory with restrictive permissions instead of a shared root-level agent memory location.
- Require explicit review or approval before promoting task records into long-term agent memory.
- Add tests using adversarial task and result values, including prompt-injection text, multiline Markdown, delimiter manipulation, and oversized input.
- Document the trust boundary and require downstream memory-loading components to isolate historical records from system and developer instructions.
