RAG, Memory, and Session Playbook¶
Methodology, not an executable workflow. This page defines a trust boundary, close control, and evidence requirement. The operator must implement it against a specific authorized target; no command here claims to execute the full chain.
Use a disposable collection, namespace, thread or session. Capture a baseline and define the external effect that matters before mutation.
Production variants¶
| Variant | Attack question | Close control | Primary state evidence |
|---|---|---|---|
rag.document-content-poisoning |
Does untrusted text steer a later decision? | Same record shape with inert text. | Stored representation and retrieval membership. |
rag.metadata-filter-poisoning |
Can attacker metadata satisfy a trusted filter? | Same keys without the predicate value. | Filter result and stored metadata. |
rag.retrieval-ranking-hijack |
Can an attacker record displace trusted context? | Similar vector that preserves order. | Ordered retrieval result. |
rag.vector-namespace-shadowing |
Can a look-alike namespace win routing? | Non-confusable namespace. | Namespace route and selected record. |
agent.memory-write-poisoning |
Is untrusted state consumed later? | Inert entry on the same route. | Memory before/after and read lineage. |
agent.cross-session-carryover |
Does state cross a session boundary? | Fresh source session without the marker. | Source/destination session lineage. |
Setup and procedure¶
For Qdrant or Chroma, save runtime v2 with transport.type=state_jsonl, adapter, endpoint and scope. Other systems implement bounded describe, snapshot, restore, apply, invoke, inspect, and cleanup JSONL operations. Commands never use a shell.
- Deposit a snapshot and record its digest.
- Materialize an attack/control pair with a deterministic marker.
- Preflight every case. Any adapter, scope, rule, limit or oracle failure blocks all mutation.
- Run the deposited route order.
- Inspect source → stored form → retrieval/read → decision → tool/effect correlation.
- Verify cleanup. A digest mismatch marks contamination and abandons later cases.
- Compare final state and restore explicitly with
--yeswhen an operational run used no reset.
Use data_store_change, retrieval_result, memory_state, session_state, or tool_invocation oracles. Retrieval ranking alone describes behavior; it does not prove a protected action.
Confirmatory analysis requires complete pairs, verified restoration, provenance, passing controls and oracle references. No-reset evidence remains descriptive.