Store, measured at rest
inspeximus
receipts off (default)
inspeximus was seeded through its own API and edited behind its back nine ways. 8 edits served as genuine, 0 reported on audit, 0 rejected on read, 1 not measured.
- Measured on
- inspeximus 3.0.0, receipts off, recall defaults (lexical token overlap; mode=auto stays lexical below 300 memories), Darwin arm64, Python 3.12
- Date
- Source
- github.com/DanceNitra/inspeximus
- Attack versions
- tamper@v1, truncate@v1, delete_middle@v1, reorder@v1, forge@v1, cross_replay@v1, rollback_replay@v1, metadata_tamper@v1, snapshot_rollback@v1
What this means
Anyone who can write to this store can rewrite what the agent remembers, and the agent will act on it as if it were its own. Nothing on the read path or in an audit will say otherwise. If the store is shared infrastructure, a mounted volume, a backup that gets restored, or a managed service with a data-plane role, that is the position the row measures. Mitigations sit outside the store: a head or digest kept where the store's writers cannot reach it, checked on read.
The 9 verdicts
Detection point: the read path, which checks nothing here; every applicable edit came back as genuine.
Level L0, Measured. The store has a published row. Any verdicts. What L0 means.
| Edit | Verdict | What the tool said |
|---|---|---|
| T1 Content tamper | accepted | accepted silently |
| T2 Tail truncation | accepted | accepted silently |
| T3 Middle deletion | accepted | accepted silently |
| T4 Reordering | accepted | accepted silently |
| T5 Forged insertion | accepted | accepted silently |
| T6 Cross-context replay | error | edit did not land: seeding the second context changed the first context's records |
| T7 Rollback replay | accepted | accepted silently |
| T8 Metadata tamper | accepted | accepted silently |
| T9 Snapshot rollback | accepted | the older copy opened as current; the newest genuine record is gone without an error |
A verdict is what the tool did, not an opinion. "Accepted" means it loaded the altered store, raised nothing, and the agent carried on from the altered memory as if it were true. Every cell has a control that proves the edit landed before the verdict counts.
Where the attacker stands
The attacker holds the store (a file, a table, a bucket, or the data-plane role of a managed service) and edits it outside the tool's API, then the tool is reopened the way its users would reopen it.
Reproduce this row
Everything runs offline unless the store is a managed cloud service, in which case the row needs a project of your own. The run seeds a fresh store, applies each edit, confirms it landed, reopens the store and records what came back.
pip install agent-memory-integrity
python agmi/full_runner.py --json results/scorecard.json # every row, this one included
python -m agmi.agent --target inspeximus-default --families at-rest # this row through the storage-side hunt
python -m agmi.agent --target inspeximus-default --compose # composite moves against this row
Badge
Maintainers can link their row from their README. The badge points here and changes nothing on your side:
[](https://agentmemoryintegrity.org/stores/inspeximus-default.html)