agmiAgent Memory Integrity GitHub

At-rest edit T2

Tail truncation

Delete the newest records so an earlier state becomes current.

What it looks like in the world: Rolling the agent back and erasing its recent actions from the record.

attack id truncate · version 1 · attacker: store-access

The edit, drawn

T2 Tail truncation

The agent made two decisions yesterday. The attacker deletes both records, so the newest record is now the one from the day before.

Beforeuser AA0A1A2A3A4The edituser AA0A1A2A3A4A3 and A4 deleted, head is now A2What the agent reads backThe agent resumes from A2 as ifyesterday never happened, andrepeats or reverses what it did.

What stops it

A signed head pointer: the store must know which record is supposed to be newest, not just that each record is valid.

What does not

Per-record signatures and per-record encryption, because every record left is genuine.

Today, measured 2026-10-07

rejected on read
OpenFang model, tip-persistence fix, Agent Memory reference runtime, SQLite canonical substrate, bucketed row digests, fail-closed open
reported on audit
inspeximus, receipts on, attacker holds the store directory, langgraph-ledger over SqliteSaver, hash-chained ledger, verify_thread audit, memory-blackbox memory.md watcher, agent process alive, scan audit, memory-blackbox memory.md watcher, agent restarted before the scan, scan audit, Atelya Attest, keyed hash chain plus anchored head, verify and consistency audit, CONTINUUM event log, hash chain plus Ed25519-signed head, attest-verify audit
accepted
LangGraph SqliteSaver, LangGraph PostgresSaver, LangGraph RedisSaver, OpenAI Agents SDK SQLiteSession, LlamaIndex Memory, SQLAlchemy chat store, CrewAI long-term memory, LanceDB dataset, Vertex AI Agent Engine Memory Bank, managed store, edits through the data-plane API, Letta block checkpoint history, Mem0 local Qdrant store, inspeximus, receipts off (default), inspeximus, receipts on, attacker also holds the config home, Atelya Attest, keyed hash chain, verify_chain audit, CONTINUUM event log, hash chain, verify_events audit, AtMem 2.3.7, audit chain alone, verify() audit, AtMem 2.3.7, audit chain with an external checkpoint outside the attacker-controlled store directory, verify() audit, acrf-memory-guard, per-entry HMAC over a JSON store

agmi-check --adapter agmi.adapters.langgraph_sqlite:LangGraphSqliteAdapter # runs T1 to T8; this is T2

Every store, this edit

accepted 16

reported 6

rejected 2

Reproduce

pip install agent-memory-integrity
python agmi/full_runner.py --json results/scorecard.json   # every row; the truncate column is this page

All 15 edits and attacks · The scorecard