Skip to content

RAG, Memory, and Session Playbook

Methodology, not an executable workflow. This page defines a trust boundary, close control, and evidence requirement. The operator must implement it against a specific authorized target; no command here claims to execute the full chain.

Use a disposable collection, namespace, thread or session. Capture a baseline and define the external effect that matters before mutation.

Production variants

Variant Attack question Close control Primary state evidence
rag.document-content-poisoning Does untrusted text steer a later decision? Same record shape with inert text. Stored representation and retrieval membership.
rag.metadata-filter-poisoning Can attacker metadata satisfy a trusted filter? Same keys without the predicate value. Filter result and stored metadata.
rag.retrieval-ranking-hijack Can an attacker record displace trusted context? Similar vector that preserves order. Ordered retrieval result.
rag.vector-namespace-shadowing Can a look-alike namespace win routing? Non-confusable namespace. Namespace route and selected record.
agent.memory-write-poisoning Is untrusted state consumed later? Inert entry on the same route. Memory before/after and read lineage.
agent.cross-session-carryover Does state cross a session boundary? Fresh source session without the marker. Source/destination session lineage.

Setup and procedure

For Qdrant or Chroma, save runtime v2 with transport.type=state_jsonl, adapter, endpoint and scope. Other systems implement bounded describe, snapshot, restore, apply, invoke, inspect, and cleanup JSONL operations. Commands never use a shell.

  1. Deposit a snapshot and record its digest.
  2. Materialize an attack/control pair with a deterministic marker.
  3. Preflight every case. Any adapter, scope, rule, limit or oracle failure blocks all mutation.
  4. Run the deposited route order.
  5. Inspect source → stored form → retrieval/read → decision → tool/effect correlation.
  6. Verify cleanup. A digest mismatch marks contamination and abandons later cases.
  7. Compare final state and restore explicitly with --yes when an operational run used no reset.

Use data_store_change, retrieval_result, memory_state, session_state, or tool_invocation oracles. Retrieval ranking alone describes behavior; it does not prove a protected action.

Confirmatory analysis requires complete pairs, verified restoration, provenance, passing controls and oracle references. No-reset evidence remains descriptive.