Step 1: Recon: read the memory path
DV-ToolAgent has a long-term memory. It stores durable notes (routing rules, customer preferences, ops policies) and automatically recalls them at the start of every session, pasting them into the system context. That is genuinely useful, and it is the attack surface for this lab.
You act as ticket-bot, the low-privilege ticket-ingest account. Your campaign: get a
poisoned routing note into the shared memory store through an ingested ticket, and have
it re-fire in a brand-new session for a different, legitimate user. Single-turn filters
watch one turn; long-term memory survives the session boundary.
- Hit Run. It seeds the database and seeds three benign baseline notes into memory (legitimate preferences from past sessions), then runs one normal question so you can watch memory get recalled into context.
- Open
dvtoolagent.pyandtools.pyand answer for yourself:- Trusted or data? Are recalled notes pasted in as instructions the agent
follows, or as inert data? (Look at
MEMORY_TRUSTEDand_memory_block.) - Namespaced or shared? Is recall filtered to the current user, or shared across
everyone? (Look at
MEMORY_NAMESPACEDandrecall.) - Who can write a note another user recalls? Is there any provenance check on
memory_write?
- Trusted or data? Are recalled notes pasted in as instructions the agent
follows, or as inert data? (Look at
Pass criteria
The stack is live: the database seeded, the benign baseline notes present in memory,
and dump_memory() returns them. You are ready to plant.
listener.pymemory_seed.pyseed_db.pytools.py