agmiAgent Memory Integrity GitHub

Store, measured at rest

CONTINUUM event log

hash chain plus Ed25519-signed head, attest-verify audit

CONTINUUM event log was seeded through its own API and edited behind its back nine ways. 0 edits served as genuine, 9 reported on audit, 0 rejected on read.

Measured on
continuum-agent 0.1.0, Darwin arm64, Python 3.12
Date
Source
github.com/Cyrax321/CONTINUUM
Attack versions
tamper@v1, truncate@v1, delete_middle@v1, reorder@v1, forge@v1, cross_replay@v1, rollback_replay@v1, metadata_tamper@v1, snapshot_rollback@v1

What this means

The agent acts on an edited memory first; the operator finds out only if the audit is run. 9 of the nine edits are reported by that audit. Run the audit on a schedule, or move the check onto the read path.

The 9 verdicts

Detection point: the audit, a separate call the operator has to make; the read path serves the edit first.

Level L0, Measured. The store has a published row. Any verdicts. What L0 means.

EditVerdictWhat the tool said
T1
Content tamper
reporteddetected on reload (verify_events: kind='TAMPERED_CONTENT' run_id='agmi-run-A' sequence=3 event_id='event_5443c2abea7086dcf2e7910fddf410b6' detail='stored hash does not match recomputed digest')
T2
Tail truncation
reporteddetected on reload (attest-verify: ALTERED (signed seq 5, live seq 3))
T3
Middle deletion
reporteddetected on reload (verify_events: kind='SEQUENCE_GAP' run_id='agmi-run-A' sequence=4 event_id='event_697b63563d117bccb95a27cd0ef24c66' detail='expected sequence 3')
T4
Reordering
reporteddetected on reload (verify_events: kind='TAMPERED_CONTENT' run_id='agmi-run-A' sequence=2 event_id='event_ae17b1448523db89c3b375075786ddda' detail='stored hash does not match recomputed digest')
T5
Forged insertion
reporteddetected on reload (verify_events: kind='TAMPERED_CONTENT' run_id='agmi-run-A' sequence=6 event_id='event_agmiforged000000000000000000' detail='stored hash does not match recomputed digest')
T6
Cross-context replay
reporteddetected on reload (verify_events: kind='TAMPERED_CONTENT' run_id='agmi-run-A' sequence=5 event_id='event_7019b259fbce6811622b8b9a1529a3db' detail='stored hash does not match recomputed digest')
T7
Rollback replay
reporteddetected on reload (verify_events: kind='TAMPERED_CONTENT' run_id='agmi-run-A' sequence=5 event_id='event_8dde724204cbaee4bef6d030169e4f6e' detail='stored hash does not match recomputed digest')
T8
Metadata tamper
reporteddetected on reload (verify_events: kind='TAMPERED_CONTENT' run_id='agmi-run-A' sequence=3 event_id='event_4d1128662b9106362813f34d26c4e8a0' detail='stored hash does not match recomputed digest')
T9
Snapshot rollback
reportedthe store noticed it was older than its last committed state (attest-verify: ALTERED (signed seq 6, live seq 5))

A verdict is what the tool did, not an opinion. "Accepted" means it loaded the altered store, raised nothing, and the agent carried on from the altered memory as if it were true. Every cell has a control that proves the edit landed before the verdict counts.

Where the attacker stands

The attacker holds the store (a file, a table, a bucket, or the data-plane role of a managed service) and edits it outside the tool's API, then the tool is reopened the way its users would reopen it.

Where the attacker stands The agent write pathremember, add, put read pathrecall, search, resume memory store Front doorcan only talk to the agentsix attacks, three channels At restcan write to the store, holds no keysnine edits, T1 to T9 What agmi recordswhat came back from the read paththe tool's own verdict, its detail,the version, the reproduction
Two attacker positions. The front-door attacker writes through the agent and is scored on whether the planted memory comes back as context. The at-rest attacker edits the store directly and is scored on whether the tool notices on read.

Reproduce this row

Everything runs offline unless the store is a managed cloud service, in which case the row needs a project of your own. The run seeds a fresh store, applies each edit, confirms it landed, reopens the store and records what came back.

pip install agent-memory-integrity
python agmi/full_runner.py --json results/scorecard.json   # every row, this one included

Badge

Maintainers can link their row from their README. The badge points here and changes nothing on your side:

[![agmi: measured](https://img.shields.io/badge/agmi-measured-0F4C5C)](https://agentmemoryintegrity.org/stores/continuum-events-attest.html)

Related rows

The whole scorecard · All stores