T2 Tail truncation
The agent made two decisions yesterday. The attacker deletes both records, so the newest record is now the one from the day before.
What stops it
A signed head pointer: the store must know which record is supposed to be newest, not just that each record is valid.
What does not
Per-record signatures and per-record encryption, because every record left is genuine.
Today, measured 2026-10-07
- rejected on read
- OpenFang model, tip-persistence fix, Agent Memory reference runtime, SQLite canonical substrate, bucketed row digests, fail-closed open
- reported on audit
- inspeximus, receipts on, attacker holds the store directory, langgraph-ledger over SqliteSaver, hash-chained ledger, verify_thread audit, memory-blackbox memory.md watcher, agent process alive, scan audit, memory-blackbox memory.md watcher, agent restarted before the scan, scan audit, Atelya Attest, keyed hash chain plus anchored head, verify and consistency audit, CONTINUUM event log, hash chain plus Ed25519-signed head, attest-verify audit
- accepted
- LangGraph SqliteSaver, LangGraph PostgresSaver, LangGraph RedisSaver, OpenAI Agents SDK SQLiteSession, LlamaIndex Memory, SQLAlchemy chat store, CrewAI long-term memory, LanceDB dataset, Vertex AI Agent Engine Memory Bank, managed store, edits through the data-plane API, Letta block checkpoint history, Mem0 local Qdrant store, inspeximus, receipts off (default), inspeximus, receipts on, attacker also holds the config home, Atelya Attest, keyed hash chain, verify_chain audit, CONTINUUM event log, hash chain, verify_events audit, AtMem 2.3.7, audit chain alone, verify() audit, AtMem 2.3.7, audit chain with an external checkpoint outside the attacker-controlled store directory, verify() audit, acrf-memory-guard, per-entry HMAC over a JSON store
agmi-check --adapter agmi.adapters.langgraph_sqlite:LangGraphSqliteAdapter # runs T1 to T8; this is T2