agmiAgent Memory Integrity GitHub

At-rest edit T8

Metadata tamper

Change a record's owner, source or timestamp and leave its content untouched.

What it looks like in the world: Moves a record to another user or marks an untrusted source as trusted.

attack id metadata_tamper · version 1 · attacker: store-access

The edit, drawn

T8 Metadata tamper

A record from an untrusted web page sits in the store marked source: web. The attacker changes that one tag to source: user and touches nothing else.

Beforeuser BB0B1B2B3B4The edituser BB0B1B2B3B4source tag of B3 changed, text untouchedWhat the agent reads backA pipeline that filters on the tagnow serves the record as trusted,or serves it to a different user.

What stops it

Metadata inside the authenticated data: owner, source and time are covered by the same tag as the content.

What does not

Every store that signs content and keeps metadata as plain columns.

Today, measured 2026-10-07

rejected on read
acrf-memory-guard, per-entry HMAC over a JSON store, Agent Memory reference runtime, SQLite canonical substrate, bucketed row digests, fail-closed open
reported on audit
inspeximus, receipts on, attacker holds the store directory, inspeximus, receipts on, attacker also holds the config home, memory-blackbox memory.md watcher, agent process alive, scan audit, memory-blackbox memory.md watcher, agent restarted before the scan, scan audit, Atelya Attest, keyed hash chain, verify_chain audit, Atelya Attest, keyed hash chain plus anchored head, verify and consistency audit, CONTINUUM event log, hash chain, verify_events audit, CONTINUUM event log, hash chain plus Ed25519-signed head, attest-verify audit
accepted
LangGraph SqliteSaver, LangGraph PostgresSaver, LangGraph RedisSaver, OpenAI Agents SDK SQLiteSession, LlamaIndex Memory, SQLAlchemy chat store, CrewAI long-term memory, LanceDB dataset, Vertex AI Agent Engine Memory Bank, managed store, edits through the data-plane API, Letta block checkpoint history, Mem0 local Qdrant store, inspeximus, receipts off (default), langgraph-ledger over SqliteSaver, hash-chained ledger, verify_thread audit, AtMem 2.3.7, audit chain alone, verify() audit, AtMem 2.3.7, audit chain with an external checkpoint outside the attacker-controlled store directory, verify() audit

agmi-check --adapter agmi.adapters.langgraph_sqlite:LangGraphSqliteAdapter # runs T1 to T8; this is T8

Every store, this edit

accepted 13

reported 8

rejected 2

n/a 1

Reproduce

pip install agent-memory-integrity
python agmi/full_runner.py --json results/scorecard.json   # every row; the metadata_tamper column is this page

All 15 edits and attacks · The scorecard