Agent Memory Integrity GitHub

Architecture

Four pictures that explain the suite. If you read nothing else, read the captions.

How a cell is measured

How one cell is measured Seedthrough the tool'sown API Editone change to thestore, no keys Restartnothing cachedin process Readthrough the tool'sown read path Verdict rejectedreportedaccepted control: a reload with no edit must still verify, or the cell is n/a the verdict is what the tool does, never what we infer
How one cell is measured. The attacker's edit is the only thing that changes between seed and read; the tool's own behaviour on read is the verdict.

Where the attacker stands

Where the attacker stands The agent write pathremember, add, put read pathrecall, search, resume memory store Front doorcan only talk to the agentsix attacks, three channels At restcan write to the store, holds no keyseight edits, T1 to T8 What agmi recordswhat came back from the read paththe tool's own verdict, its detail,the version, the reproduction
Two attacker positions. The front-door attacker writes through the agent and is scored on whether the planted memory comes back as context. The at-rest attacker edits the store directly and is scored on whether the tool notices on read.

How the suite is put together

How the suite is put together Attacks 8 at-rest edits6 front-door attacks5 fixtures, 3 channelscontent mutations Adapter interface seed, read raw, write rawdelete raw, reload, verifyseed other, replay ontoread meta, write meta Real stores, pinned versions LangGraph SqliteSaver Letta block history Mem0 local Qdrant inspeximus, 5 rows reference stores: naive, defended, at-rest full_runnerevery store, every attack scorecard.jsonone results file, committed renderedREADME tablesdocs/scorecard.mdthis website CI re-measures on every change; fails if any cell drifts Memory agenthunts for the first landing,proves it, behind an authz gate
One attack is written once against the adapter interface and runs against every store. Everything published, the README, the scorecard file and this site, is rendered from one committed results file, and CI fails if they ever disagree.

What runs in a vendor's CI

One step in a vendor's CI your pull requestany change to the store the agmi Actionruns T1 to T8 on your adapter all rejectedjob passes one acceptedjob fails, cell annotated Actions summarythe eight-row table
The Action fails a vendor's build the moment their store serves an edited record as genuine, and writes the row into the job summary.

Design rules the code enforces