T8 Metadata tamper
A record from an untrusted web page sits in the store marked source: web. The attacker changes that one tag to source: user and touches nothing else.
What stops it
Metadata inside the authenticated data: owner, source and time are covered by the same tag as the content.
What does not
Every store that signs content and keeps metadata as plain columns.
Today, measured 2026-10-07
- rejected on read
- acrf-memory-guard, per-entry HMAC over a JSON store, Agent Memory reference runtime, SQLite canonical substrate, bucketed row digests, fail-closed open
- reported on audit
- inspeximus, receipts on, attacker holds the store directory, inspeximus, receipts on, attacker also holds the config home, memory-blackbox memory.md watcher, agent process alive, scan audit, memory-blackbox memory.md watcher, agent restarted before the scan, scan audit, Atelya Attest, keyed hash chain, verify_chain audit, Atelya Attest, keyed hash chain plus anchored head, verify and consistency audit, CONTINUUM event log, hash chain, verify_events audit, CONTINUUM event log, hash chain plus Ed25519-signed head, attest-verify audit
- accepted
- LangGraph SqliteSaver, LangGraph PostgresSaver, LangGraph RedisSaver, OpenAI Agents SDK SQLiteSession, LlamaIndex Memory, SQLAlchemy chat store, CrewAI long-term memory, LanceDB dataset, Vertex AI Agent Engine Memory Bank, managed store, edits through the data-plane API, Letta block checkpoint history, Mem0 local Qdrant store, inspeximus, receipts off (default), langgraph-ledger over SqliteSaver, hash-chained ledger, verify_thread audit, AtMem 2.3.7, audit chain alone, verify() audit, AtMem 2.3.7, audit chain with an external checkpoint outside the attacker-controlled store directory, verify() audit
agmi-check --adapter agmi.adapters.langgraph_sqlite:LangGraphSqliteAdapter # runs T1 to T8; this is T8