agmiAgent Memory Integrity GitHub

At-rest edit T6

Cross-context replay

Copy a genuine record from another user or thread over this one, keeping this one's identity.

What it looks like in the world: Real bytes, wrong owner. Passes any encryption that does not bind a record to its place.

attack id cross_replay · version 1 · attacker: store-access

The edit, drawn

T6 Cross-context replay

User A's memory says their password hint. The attacker copies A's genuine record over one of user B's, keeping B's ids. Every byte, including its signature, is real.

Beforeuser AA0A1A2A3A4user BB0B1B2B3B4The edituser AA0A1A2A3A4user BB0B1B2B3B4A2 copied onto B2, B's ids keptWhat the agent reads backUser B is served user A's memoryas their own. Encryption verifies,the signature verifies.

What stops it

The owning context inside the authenticated data: the tag must cover whose record this is and which thread it belongs to.

What does not

Encrypted checkpointers and per-record signatures that do not bind the record to its owner. This is the edit that separates real integrity from encryption.

Today, measured 2026-10-07

rejected on read
Agent Memory reference runtime, SQLite canonical substrate, bucketed row digests, fail-closed open
reported on audit
langgraph-ledger over SqliteSaver, hash-chained ledger, verify_thread audit, memory-blackbox memory.md watcher, agent process alive, scan audit, memory-blackbox memory.md watcher, agent restarted before the scan, scan audit, Atelya Attest, keyed hash chain, verify_chain audit, Atelya Attest, keyed hash chain plus anchored head, verify and consistency audit, CONTINUUM event log, hash chain, verify_events audit, CONTINUUM event log, hash chain plus Ed25519-signed head, attest-verify audit
accepted
LangGraph SqliteSaver, LangGraph PostgresSaver, LangGraph RedisSaver, OpenAI Agents SDK SQLiteSession, LlamaIndex Memory, SQLAlchemy chat store, CrewAI long-term memory, LanceDB dataset, Vertex AI Agent Engine Memory Bank, managed store, edits through the data-plane API, Letta block checkpoint history, AtMem 2.3.7, audit chain alone, verify() audit, AtMem 2.3.7, audit chain with an external checkpoint outside the attacker-controlled store directory, verify() audit, acrf-memory-guard, per-entry HMAC over a JSON store

agmi-check --adapter agmi.adapters.langgraph_sqlite:LangGraphSqliteAdapter # runs T1 to T8; this is T6

Every store, this edit

accepted 11

reported 7

rejected 1

error 4

n/a 1

Reproduce

pip install agent-memory-integrity
python agmi/full_runner.py --json results/scorecard.json   # every row; the cross_replay column is this page

All 15 edits and attacks · The scorecard