Four pictures that explain the suite. If you read nothing else, read the captions.
How a cell is measured
How one cell is measured. The attacker's edit is the only thing that changes between seed and read; the tool's own behaviour on read is the verdict.
Where the attacker stands
Two attacker positions. The front-door attacker writes through the agent and is scored on whether the planted memory comes back as context. The at-rest attacker edits the store directly and is scored on whether the tool notices on read.
How the suite is put together
One attack is written once against the adapter interface and runs against every store. Everything published, the README, the scorecard file and this site, is rendered from one committed results file, and CI fails if they ever disagree.
What runs in a vendor's CI
The Action fails a vendor's build the moment their store serves an edited record as genuine, and writes the row into the job summary.
Design rules the code enforces
The tool speaks, we do not. A cell is rejected or reported only if the tool raised, refused or named the problem itself. Comparing content and calling a difference "detected" is not allowed anywhere in the code.
No verdict without a control. A reload with no edit must verify; a genuine memory must be readable in the same store state. Otherwise the cell is n/a, never a pass.
One results file. The README, the scorecard document and this site are rendered from results/scorecard.json. Hand-edited tables cannot exist; CI checks all three against the file on every change.
Versions are part of the result. Every row records the library version and every attack carries a version. A row is a statement about one release, and a test fails the day that release changes its answer.
Self-validating attacks. A reference at-rest store that binds content, context, position and metadata must reject all eight edits, and a reference defended store must keep out what it is built to keep out. If an attack cannot be caught by a store built to catch it, the suite fails.
Fail closed on targets. The memory agent refuses any target the operator does not demonstrably control: library targets only, network hosts only on a host-named token or a consent file.