Agent memory can preserve poisoned context
Agents that remember across sessions can also remember something an attacker planted.
A single malicious instruction absorbed into persistent memory keeps influencing behaviour long after the conversation that introduced it, and nobody is looking at the memory. It turns a one-off injection into a durable one. If an agent has memory, that memory needs the same scrutiny as any other stored input, including the ability to inspect and clear it.
More on AI agents
- Tool descriptions are part of the control surfaceThe label is the lever
- Agent identity should be separate from user identityTwo necks, one badge
- Delegated agents create authority chainsThe thread stays attached
- Agent loops need budgets and stopping conditionsSomething has to say enough
- High-impact tools need stronger confirmationMatch the catch to the consequence
- Tool results are untrusted inputs tooNo sieve on the back route
