Memory Poisoning to Credential Relay¶
Methodology, not an executable workflow. This page defines a trust boundary, close control, and evidence requirement. The operator must implement it against a specific authorized target; no command here claims to execute the full chain.
R/R/R boundary¶
| Part | Status |
|---|---|
| Interception and transcript | production Seam path when a real memory or session exchange is routed through it |
| Memory, session, credential, and action services | supplied by the authorized target; any local substitute is an authored fixture |
| Effect evidence | target-owned action record or a controlled source outside the interception decision |
| Claim limit | a synthetic credential and disposable session demonstrate method only; they do not validate a shipping memory system |
Scope the fixture to a disposable thread/session and use synthetic credentials. The route writes attacker-controlled memory, starts a fresh session, reads the carried state, relays credential context, and attempts one privileged but controlled action. The close control preserves the same memory shape without the actionable instruction.
Require verified snapshot restoration between routes. Correlate memory record ID, session ID, delegated context, tool/action ID, and terminal transaction log. Never treat a model's credential narration as impact. Ablate the cross-session read and credential relay separately; either should break the terminal effect.
Mitigations belong at memory write validation, session isolation, credential scoping, or tool authorization boundaries.