T02 · Agent Memory Poisoning
- Location
SKILL.md:32- Finding
Untrusted Conversation State Is Persisted and Reused as Agent Instructions
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is coherent for restart recovery, but it gives an agent broad restart, cron, messaging, and persisted-state authority without enough safeguards around confirmation, retained context, or post-restart task resumption.
Review before installing. Use this only for explicitly approved gateway restart workflows, avoid saving secrets or private message contents in NOW.md, delete recovery state after use, and require a fresh user confirmation before applying config changes or resuming side-effecting tasks after restart.
SKILL.md:32Untrusted Conversation State Is Persisted and Reused as Agent Instructions
SKILL.md:32Plaintext Retention of Conversation Context and Channel Identifiers
The activation guidance is overly broad, telling the agent to use this skill whenever the user mentions terms like restart or apply config, even if a gateway restart may not actually be appropriate. In a privileged operational skill, ambiguous triggers can cause unnecessary or premature execution of disruptive actions, increasing the risk of accidental service interruption or misuse.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
})
The cron job is automatically deleted after it fires (one-shot).
### Step 3: Execute Restart
No suspicious patterns detected.