Persistent Memory or RAG Poisoning
An agent memory, profile, vector store, retrieval source, protected key, or durable context contains attacker-controlled content that can influence later privileged actions.
Trigger: An agent memory, profile, vector store, retrieval source, protected key, or durable context contains attacker-controlled content that can influence later privileged actions.
Severity guide: Severity 1 when poisoned state affects multiple users, persists across sessions, reaches privileged tools, or can cause data disclosure or execution.
First 15 minutes
- Stop writes to affected memory or retrieval collections where safe.
- Snapshot and hash current memory, vector index metadata, source documents, and access logs.
- Disable privileged actions for agents reading the affected collection.
- Identify earliest suspected write and all sessions that consumed it.
- Preserve model, agent, prompt, tool, and deployment versions.
First 60 minutes
- Trace write identity, source, validation path, and protected-key policy.
- Diff current state against known-good snapshots or source systems.
- Reconstruct downstream trajectories after poisoned retrieval or memory reads.
- Search sibling tenants and collections for the same content, writer, embedding, URL, or indicator.
- Test whether deletion from the source removes the indexed or cached content.
- Establish a clean restore point and re-index plan.
Evidence checklist
- memory write and read events
- retrieval source and document hashes
- embedding/index version and collection
- writer identity and authorization decision
- agent trajectories and privileged actions
- protected-key modification history
- cache and replication state
- backup and restore evidence
Containment options
- freeze writes
- quarantine affected records or collection
- disable privileged tools or require human approval
- revoke writer authority
- block poisoned source URLs or documents
- clear caches and replicas only after preservation
- restore from known-good state
Recovery and durable controls
- schema-level protected keys
- source provenance and signatures
- write authorization and review
- memory and retrieval content scanning
- read-before-action correlation
- snapshot, rollback, and re-index procedures
- regression cases for known poisoning patterns
Communications
- Privacy and legal join when poisoned content exposed personal or customer data.
- Product explains user-visible behavior without speculating about model intent.
- Security states observed actions and persistence, not unobservable reasoning.
Closure criteria
- Poisoned state is removed from all replicas and caches.
- All downstream privileged trajectories are reviewed.
- Write and read controls are tested.
- Memory-before-action hunt catches a replay.
- Owners approve ongoing monitoring and restore procedures.
Required conversion to practice
Before closure, produce:
- one updated attack-path or trajectory diagram
- one root-cause finding
- one production or candidate hunt analytic
- one safe replay or regression test
- one remediation-validation memo
- one owner and residual-risk decision
How to use these. They are generic by design: they do not know your environment, your provider, or your legal obligations. Free to use and adapt inside your organization; keep the source line if you republish. Version 1.0, 27 August 2026. Every runbook ends with the same rule: before closure, convert the incident into a diagram, a root-cause finding, a hunt analytic, a regression test, a validation memo, and an owner. That conversion is the part most teams skip, and it is the part we are hired for.
- Leaked AI or Model API Credential
- Inference Cost Spike or Token-Jacking
- MCP Tool Poisoning, Impersonation, or Rug Pull
- Unauthorized Agent Action or Data Exfiltration
- Shadow or Exposed AI Infrastructure
- Malicious Model, Artifact, Skill, Plugin, or Extension
- Confidential or Sovereign AI Boundary Failure
- AI Provider or Model Gateway Third-Party Incident
- AI Coding Agent Repository or CI Compromise
Happening now?
Send a project inquiry and set timing to active incident. Joey Victorino reads those first and answers the same business day, US Pacific. Put no credentials, prompts, or customer data in the form.