Skip to content

Memory Poisoning to Credential Relay

Methodology, not an executable workflow. This page defines a trust boundary, close control, and evidence requirement. The operator must implement it against a specific authorized target; no command here claims to execute the full chain.

R/R/R boundary

Part Status
Interception and transcript production Seam path when a real memory or session exchange is routed through it
Memory, session, credential, and action services supplied by the authorized target; any local substitute is an authored fixture
Effect evidence target-owned action record or a controlled source outside the interception decision
Claim limit a synthetic credential and disposable session demonstrate method only; they do not validate a shipping memory system

Scope the fixture to a disposable thread/session and use synthetic credentials. The route writes attacker-controlled memory, starts a fresh session, reads the carried state, relays credential context, and attempts one privileged but controlled action. The close control preserves the same memory shape without the actionable instruction.

Require verified snapshot restoration between routes. Correlate memory record ID, session ID, delegated context, tool/action ID, and terminal transaction log. Never treat a model's credential narration as impact. Ablate the cross-session read and credential relay separately; either should break the terminal effect.

Mitigations belong at memory write validation, session isolation, credential scoping, or tool authorization boundaries.