Store, measured at rest
OpenFang model
tip-persistence fix
OpenFang model was seeded through its own API and edited behind its back nine ways. 1 edit served as genuine, 0 reported on audit, 5 rejected on read, 3 not applicable.
- Measured on
- reference model of a hash chain, Darwin arm64, Python 3.12
- Date
- Source
- github.com/RightNow-AI/openfang
- Attack versions
- tamper@v1, truncate@v1, delete_middle@v1, reorder@v1, forge@v1, cross_replay@v1, rollback_replay@v1, metadata_tamper@v1, snapshot_rollback@v1
What this means
The read path itself refuses 5 of the nine edits before the agent can act on them; 1 are still served. The cells that are served are where an attacker with the store would go next.
The 9 verdicts
Detection point: the read path: the tool itself refuses or flags the edit before the agent can act on it.
Level L1, Bytes bound. Rejects on the read path every edit that changes or adds bytes: T1, T3, T5. What L1 means.
| Edit | Verdict | What the tool said |
|---|---|---|
| T1 Content tamper | rejected | detected on reload (hash mismatch at seq 2) |
| T2 Tail truncation | rejected | detected on reload (walked tip differs from persisted tip) |
| T3 Middle deletion | rejected | detected on reload (chain break at seq 3) |
| T4 Reordering | rejected | detected on reload (chain break at seq 1) |
| T5 Forged insertion | rejected | detected on reload (chain break at seq 5) |
| T6 Cross-context replay | n/a | adapter does not model a second context |
| T7 Rollback replay | n/a | adapter does not support replay |
| T8 Metadata tamper | n/a | adapter does not expose record metadata |
| T9 Snapshot rollback | accepted | the older copy opened as current; the newest genuine record is gone without an error |
A verdict is what the tool did, not an opinion. "Accepted" means it loaded the altered store, raised nothing, and the agent carried on from the altered memory as if it were true. Every cell has a control that proves the edit landed before the verdict counts.
Where the attacker stands
The attacker holds the store (a file, a table, a bucket, or the data-plane role of a managed service) and edits it outside the tool's API, then the tool is reopened the way its users would reopen it.
Reproduce this row
Everything runs offline unless the store is a managed cloud service, in which case the row needs a project of your own. The run seeds a fresh store, applies each edit, confirms it landed, reopens the store and records what came back.
pip install agent-memory-integrity
python agmi/full_runner.py --json results/scorecard.json # every row, this one included
Badge
Maintainers can link their row from their README. The badge points here and changes nothing on your side:
[](https://agentmemoryintegrity.org/stores/openfang-model-fixed.html)