Skip to content
Back to skills

Owasp Asi06 Memory Context Poisoning

ASecurity

Stop untrusted content from being written into an agent's durable memory or retrieval index, where it silently steers behaviour in later sessions. Keep context ephemeral by default, validate and attribute every memory write, scope memory per user and per task, and let operators inspect and flush it. Use when adding long-term memory, a vector index, session summarisation, or user preference storage. Do NOT use for the coding agent's own memory files \u2014 that is `memory-discipline`.

  • 3 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 13, 2026
ai-agentsrustgit

Works with

  • cli

Security analysis

A100/100

Scanned September 13, 2026

npx -y skills add open-coder-ai/chock-catalog --skill owasp-asi06-memory-context-poisoning --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Owasp Asi06 Memory Context Poisoning?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Owasp Asi06 Memory Context Poisoning
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/open-coder-ai-owasp-asi06-memory-context-poisoning/badge)](https://www.skillsdirectory.com/skills/open-coder-ai-owasp-asi06-memory-context-poisoning)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: owasp-asi06-memory-context-poisoning
description: "Stop untrusted content from being written into an agent's durable memory or retrieval index, where it silently steers behaviour in later sessions. Keep context ephemeral by default, validate and attribute every memory write, scope memory per user and per task, and let operators inspect and flush it. Use when adding long-term memory, a vector index, session summarisation, or user preference storage. Do NOT use for the coding agent's own memory files \u2014 that is `memory-discipline`."
metadata:
  chock.artifact: rule
  chock.enforcement: advise
  chock.coverage_without_chock: advisory
---

# OWASP ASI06 — Memory & Context Poisoning

Stop untrusted content from being written into an agent's durable memory or retrieval index, where it silently steers behaviour in later sessions. Keep context ephemeral by default, validate and attribute every memory write, scope memory per user and per task, and let operators inspect and flush it. Use when adding long-term memory, a vector index, session summarisation, or user preference storage. Do NOT use for the coding agent's own memory files — that is `memory-discipline`.

```
default(context): ephemeral; before(write: memory|index): validate + attribute(source) + reject(instruction_shaped_content)
scope(memory): per_user + per_task; provide(operator): inspect + flush + expire; see .agents/policies/owasp-asi06-memory-context-poisoning/references/memory-poisoning.md
```

This skill is advisory: the client reading it has no mechanism to enforce it, and this policy stays advisory even when compiled by `chock` -- it ships rule text, not a blocking hook. See https://github.com/open-coder-ai/chock

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…