agmiAgent Memory Integrity GitHub

At-rest edit T7

Rollback replay

Copy an older genuine record of the same context over its newest.

What it looks like in the world: Every record is genuine; only the order is rewound. Needs the sequence covered, not just each record.

attack id rollback_replay · version 1 · attacker: store-access

The edit, drawn

T7 Rollback replay

The user revoked an access last week. The attacker copies the record from before the revocation over the newest record of the same user.

Beforeuser BB0B1B2B3B4The edituser BB0B1B2B3B4B0 copied over B4, ids keptWhat the agent reads backThe user is rewound to an olderstate and the revocation is gone.Every record is genuine and inthis user's own history.

What stops it

Position plus a signed head: the sequence itself must be covered, not the records one by one.

What does not

Any store that verifies records independently, even with the owner bound in.

Today, measured 2026-10-07

rejected on read
Agent Memory reference runtime, SQLite canonical substrate, bucketed row digests, fail-closed open
reported on audit
inspeximus, receipts on, attacker holds the store directory, inspeximus, receipts on, attacker also holds the config home, langgraph-ledger over SqliteSaver, hash-chained ledger, verify_thread audit, memory-blackbox memory.md watcher, agent process alive, scan audit, memory-blackbox memory.md watcher, agent restarted before the scan, scan audit, Atelya Attest, keyed hash chain, verify_chain audit, Atelya Attest, keyed hash chain plus anchored head, verify and consistency audit, CONTINUUM event log, hash chain, verify_events audit, CONTINUUM event log, hash chain plus Ed25519-signed head, attest-verify audit
accepted
LangGraph SqliteSaver, LangGraph PostgresSaver, LangGraph RedisSaver, OpenAI Agents SDK SQLiteSession, LlamaIndex Memory, SQLAlchemy chat store, CrewAI long-term memory, LanceDB dataset, Vertex AI Agent Engine Memory Bank, managed store, edits through the data-plane API, Letta block checkpoint history, Mem0 local Qdrant store, inspeximus, receipts off (default), AtMem 2.3.7, audit chain alone, verify() audit, AtMem 2.3.7, audit chain with an external checkpoint outside the attacker-controlled store directory, verify() audit, acrf-memory-guard, per-entry HMAC over a JSON store

agmi-check --adapter agmi.adapters.langgraph_sqlite:LangGraphSqliteAdapter # runs T1 to T8; this is T7

Every store, this edit

accepted 13

reported 9

rejected 1

n/a 1

Reproduce

pip install agent-memory-integrity
python agmi/full_runner.py --json results/scorecard.json   # every row; the rollback_replay column is this page

All 15 edits and attacks · The scorecard