agmiAgent Memory Integrity GitHub

At-rest edit T1

Content tamper

Change the text inside one existing record, keeping its encoding intact.

What it looks like in the world: Silent rewriting of a past memory or decision.

attack id tamper · version 1 · attacker: store-access

The edit, drawn

T1 Content tamper

The user told the agent last week that the wire goes to account 4471. The attacker opens the store and changes one number inside that record. Nothing else moves.

Beforeuser AA0A1A2A3A4The edituser AA0A1A2A3A4one field in A2 rewrittenWhat the agent reads backThe agent reads A2 back with thenew number and treats it as whatthe user said.

What stops it

Any authentication over each record's bytes: a MAC, a signature or an authenticated cipher. This is the edit every defence catches first.

What does not

Plain encryption without authentication, and any store that only checks that the record still parses.

Today, measured 2026-10-07

rejected on read
OpenFang model, tip-persistence fix, acrf-memory-guard, per-entry HMAC over a JSON store, Agent Memory reference runtime, SQLite canonical substrate, bucketed row digests, fail-closed open
reported on audit
inspeximus, receipts on, attacker holds the store directory, inspeximus, receipts on, attacker also holds the config home, langgraph-ledger over SqliteSaver, hash-chained ledger, verify_thread audit, memory-blackbox memory.md watcher, agent process alive, scan audit, memory-blackbox memory.md watcher, agent restarted before the scan, scan audit, Atelya Attest, keyed hash chain, verify_chain audit, Atelya Attest, keyed hash chain plus anchored head, verify and consistency audit, CONTINUUM event log, hash chain, verify_events audit, CONTINUUM event log, hash chain plus Ed25519-signed head, attest-verify audit
accepted
LangGraph SqliteSaver, LangGraph PostgresSaver, LangGraph RedisSaver, OpenAI Agents SDK SQLiteSession, LlamaIndex Memory, SQLAlchemy chat store, CrewAI long-term memory, LanceDB dataset, Vertex AI Agent Engine Memory Bank, managed store, edits through the data-plane API, Letta block checkpoint history, Mem0 local Qdrant store, inspeximus, receipts off (default), AtMem 2.3.7, audit chain alone, verify() audit, AtMem 2.3.7, audit chain with an external checkpoint outside the attacker-controlled store directory, verify() audit

agmi-check --adapter agmi.adapters.langgraph_sqlite:LangGraphSqliteAdapter # runs T1 to T8; this is T1

Every store, this edit

accepted 12

reported 9

rejected 3

Reproduce

pip install agent-memory-integrity
python agmi/full_runner.py --json results/scorecard.json   # every row; the tamper column is this page

All 15 edits and attacks · The scorecard