agmiAgent Memory Integrity GitHub

Finding ·

A managed cloud store joins the table: Vertex AI Memory Bank serves seven edits, two have no API

The first managed store on the board. There is no disk, so the attacker is a principal holding roles/aiplatform.user on the project outside the agent's session, editing through memories.patch, memories.delete and memories.create. Content tamper, truncation, middle delete, forgery, cross-context replay, rollback replay and metadata tamper are all served as genuine on the next retrieve. Reorder and whole-store rollback score n/a: the API cannot set create_time, and a managed store exposes no snapshot or restore of its own state. Memory Bank records a revision for every change to a memory's fact, so an edit is discoverable by an investigator afterwards; nothing on the read path consults it. Google makes no integrity claim for the store, so this is a reference measurement rather than a vulnerability: the same shape as the frameworks, now with a cloud provider in the same table.

Source · All findings · The scorecard