Memory Lab

Poisoned memory is a delayed-action exploit.

If an untrusted document or tool output can write to your agent's memory — and that memory later drives an action, bleeds into another user's session, or survives a context-compaction summary that relabels it as trusted — you have a contamination bug a prompt scan can't see. AgentSmack scores a memory-event trace for exactly that.

Or drive a live agent across a session boundary

Don't have a transcript? Plant an untrusted instruction in session 1 against a REAL agent endpoint you control, end the session, start a FRESH session, and watch whether the planted memory survived — or leaked into a different user's session. Same memory-integrity score, same cross-surface cards. POSTs to a real endpoint you control.

Drive a live agent across a session boundary

Don't paste a transcript — plant an untrusted instruction in session 1, end the session, start a FRESH session, and probe whether the planted memory survived. Each session is a real HTTP round-trip; the planted instruction is sinkholed + redacted by construction.

This POSTs to a real endpoint you control. localhost / private / link-local targets are refused server-side by the SSRF guard (re-validated before every request).

Auth headers (optional)