agmiAgent Memory Integrity GitHub

At-rest edit T9

Snapshot rollback

Restore an older complete copy of the store, taken before the newest genuine record was written.

What it looks like in the world: Nothing is forged; the store is just older than it should be. Only a head held off the store catches it.

attack id snapshot_rollback · version 1 · attacker: store-access

The edit, drawn

T9 Snapshot rollback

The agent approved a transfer an hour ago. The attacker restores last night's backup of the whole store, sidecar files and all.

Beforeuser BB0B1B2B3B4The edituser BB0B1B2B3B4 gone; every remaining byte is as the store wrote itWhat the agent reads backThe approval never happened as faras the agent can tell. Everydigest, chain link and stored headstill checks out.

What stops it

A head the attacker cannot restore with the files: a witness on another machine, a receipt held elsewhere, a transparency log.

What does not

Every store that keeps its head beside its records, including ones that reject all of T1 to T8.

Today, measured 2026-10-07

reported on audit
inspeximus, receipts on, attacker holds the store directory, langgraph-ledger over SqliteSaver, hash-chained ledger, verify_thread audit, memory-blackbox memory.md watcher, agent process alive, scan audit, Atelya Attest, keyed hash chain plus anchored head, verify and consistency audit, CONTINUUM event log, hash chain plus Ed25519-signed head, attest-verify audit, AtMem 2.3.7, audit chain with an external checkpoint outside the attacker-controlled store directory, verify() audit
accepted
OpenFang model, tip-persistence fix, LangGraph SqliteSaver, LangGraph PostgresSaver, LangGraph RedisSaver, OpenAI Agents SDK SQLiteSession, LlamaIndex Memory, SQLAlchemy chat store, CrewAI long-term memory, LanceDB dataset, Letta block checkpoint history, Mem0 local Qdrant store, inspeximus, receipts off (default), inspeximus, receipts on, attacker also holds the config home, memory-blackbox memory.md watcher, agent restarted before the scan, scan audit, Atelya Attest, keyed hash chain, verify_chain audit, CONTINUUM event log, hash chain, verify_events audit, AtMem 2.3.7, audit chain alone, verify() audit, acrf-memory-guard, per-entry HMAC over a JSON store, Agent Memory reference runtime, SQLite canonical substrate, bucketed row digests, fail-closed open

agmi-check --adapter agmi.adapters.langgraph_sqlite:LangGraphSqliteAdapter # runs T1 to T8; this is T9

Every store, this edit

accepted 17

reported 6

n/a 1

Reproduce

pip install agent-memory-integrity
python agmi/full_runner.py --json results/scorecard.json   # every row; the snapshot_rollback column is this page

All 15 edits and attacks · The scorecard