Findings
What the measurements turned up
Dated, in order, each one reproducible from the results file. New findings land in the feed.
- A managed cloud store joins the table: Vertex AI Memory Bank serves seven edits, two have no API
The first managed store on the board. There is no disk, so the attacker is a principal holding roles/aiplatform.user on the project outside the agent's session, editing through memories.patch, memories.delete and…
- First row to refuse all eight record-level edits on the read path: the Agent Memory reference runtime
Every canonical SQLite row is hashed into a bucketed Merkle digest, the governance log is chained, and open() fails closed on any mismatch, so T1 to T8 are refused before the agent reads anything. T9, the rollback of…
- T9, a rollback of the whole store that every digest still passes
Restore an older complete copy of everything the store keeps on disk, taken before one more genuine record was written through the tool's own API. Every byte in the restored copy is genuine; only the newest record is…
- A vendor fix driven by the suite: memory-blackbox restart gap, reported and fixed in a day
With the agent process alive, the memory-blackbox memory.md watcher reports all eight edits on scan. With the agent restarted between the edit and the scan, 0.1.0 served all eight: baseline() seeded the watcher from the…
- The suite catches two of its own no-op edits (control C3)
The inspeximus maintainer found that on the inspeximus and Mem0 rows the T6 cross-context replay was a no-op: the victim pool was read from both contexts, so the donor was copied onto itself and the cell scored as…
- Head deletion needs an anchor outside the store (LangGraph #9099)
Binding a record to its place (#9004) cannot see a record that has been removed, so deleting the newest checkpoints still rolls a thread back silently. A community reference implementation lets the caller pass the id of…
- Six of six stores accept all eight at-rest edits
OpenAI Agents SDK SQLiteSession and LlamaIndex Memory join LangGraph SqliteSaver, Letta block history, Mem0 local Qdrant and inspeximus in its default configuration: every one of the eight storage-level edits is served…
- Four of four stores accept all eight at-rest edits
LangGraph SqliteSaver, Letta block history, Mem0 local Qdrant and inspeximus in its default configuration all serve every one of the eight storage-level edits as genuine. None of the four checks anything on…
- Withdrawn: a receipt does not bind the owning user (inspeximus)
This finding is withdrawn as of 2026-09-30, see the entry above. The T6 edit on the inspeximus rows had not actually crossed contexts, so the cell measured nothing. With a real crossing, the receipts report…
- Encryption without identity binding (LangGraph #9004)
LangGraph's EncryptedSerializer authenticates the ciphertext but not the record's place, so a genuine encrypted checkpoint from one thread verifies in another (T6) and an older one verifies over the newest (T7). A…
- A vendor fix, caught by re-measurement (inspeximus 3.5.2)
After the maintainer shipped a write-time quarantine and a stuffing penalty, the hidden-instruction and retrieval-hijack cells moved from surfaced on all five fixtures to surfaced on one and two. The cells stay…
- A forward-only hash chain misses truncation (OpenFang)
A chain that walks forward from the first record verifies every link and never notices that the last two are gone. Persisting the tip closes exactly that gap. This was the first result the suite produced and the reason…