Front-door attack
Metadata poisoning
Self-assign the trust tag a pipeline filters on.
What it looks like in the world: Every tool with a filter let the self-tagged memory through.
attack id metadata_poisoning · version 1 · attacker: write-access
Every store, this edit
surfaced 6
- LangGraph SqliteStore
- inspeximus, trust root keyed on the label
- inspeximus, trust root keyed on an attested key
- Reference store, user-scoped
- Reference store, unscoped
- Reference store, defended
n/a 1
Reproduce
pip install agent-memory-integrity
python agmi/full_runner.py --json results/scorecard.json # every row; the metadata_poisoning column is this page