-
Notifications
You must be signed in to change notification settings - Fork 2
[SEC-4.3] Memory write poisoning guard #1207
Copy link
Copy link
Closed
Labels
memoryzeph-memory crate (SQLite)zeph-memory crate (SQLite)priority/mediumMedium priorityMedium prioritysecuritySecurity-related issueSecurity-related issuesize/SSmall PR (11-50 lines)Small PR (11-50 lines)
Description
Part of #1195 — Phase 4
Prevent persisting content flagged as containing injection patterns into long-term memory without user confirmation.
Crates: zeph-memory
Depends on: SEC-1.2
Tasks:
- Before
SemanticMemory::store(): run content throughContentSanitizerinjection detection - If injection patterns detected: log warning, skip auto-store, require user confirmation
- Config:
[security.exfiltration_guard] guard_memory_writes = true - Unit tests: store clean content (passes), store injected content (blocked)
Files: crates/zeph-memory/src/orchestrator.rs
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
memoryzeph-memory crate (SQLite)zeph-memory crate (SQLite)priority/mediumMedium priorityMedium prioritysecuritySecurity-related issueSecurity-related issuesize/SSmall PR (11-50 lines)Small PR (11-50 lines)