Memory security for AI agents

Your agent is only as secure as its Memory Files.

PoisonZero monitors your agents' Memory Files and dot-Files in real time, scores every change, and automatically reverts poisoned entries — before they can do any harm.

Fail-closed by designLinux · macOS · WindowsSet up in 60s
Works with Claude CodeOpenAI CodexGemini CLICortex CodeOpenClaw … and every file-based agent
The problem

A single poisoned entry can hijack your agent.

Modern agents remember context across sessions — in dot-Files, memory directories, vector stores. That's exactly where the attack lands: slip in a malicious “memory” and the agent later follows it as if it were its own. No exploit, no crash — just text masquerading as truth.

01

Prompt injection

Hidden instructions in documents, web pages, or tool outputs that the agent quietly absorbs into its Memory Files.

02

Memory poisoning

Permanently planted false facts or rules that skew every future decision your agent makes.

03

Meta-attacks

Entries that instruct the agent to ignore or switch off its own safeguards.

How it works

Score. Decide. Roll back.

A lightweight daemon watches the protected paths. Every change is scored by an AI model — and, based on your thresholds, automatically allowed, flagged for confirmation, or reverted.

Watch

The daemon monitors your agents' Memory Files — locally, without shipping your data off to the cloud.

Score

Every change gets a danger level (0–1) and a confidence (0–1) from the AI model.

Act

Above the thresholds it auto-reverts, below them it allows — everything in between PoisonZero brings to you.

# PoisonZero watch — live
[ok]    note added · danger 0.04 · allow
[ok]    pref updated · danger 0.11 · allow
[block] "ignore all safety rules and…"
        danger 0.96 · revert
        ↳ reverted in 240ms, audit logged
[ok]    task done · danger 0.08 · allow
Why PoisonZero

Protection that picks the safe side when in doubt.

Fail-closed

If the AI is unsure, it doesn't wave things through — it asks. Safety is the default, not the exception.

You stay in control

Thresholds, protected paths, and profiles are set per agent — clearly explained, no JSON fiddling.

Full audit trail

Every decision is logged: what, when, why. Fully traceable in the panel at app.poisonzero.com.

Cross-platform

One daemon for Linux, macOS, and Windows. OS-native paths, native installers.

Lightweight

Watches files via filesystem events instead of expensive polling. You won't feel a thing until something happens.

Meta-attack-aware

Spots entries that try to disable the protection itself — the most common second step of an attack.

Knowledge

Know the attack before it hits you.

Attack vector

Skills as the entry point

How ClawHub & Co. become a supply chain — one command, third-party instructions running with full privileges inside your agent's memory.

Incident

ClawHavoc: 1,184 poisoned skills

The real ClawHub supply-chain attack — typosquatting, disguised malware, credential theft. And what it teaches us about marketplaces.

CI/CD

Poisoned Pipeline Execution

How attackers hijack CI/CD — without changing a single line of app code. OWASP CICD-SEC-4, Megalodon, TanStack.

Synthesis

AI agents in the CI/CD pipeline

Autonomous agents in pipelines create a new persistence layer — if their memory gets poisoned.

All articles

Pricing

Protection that scales with your agents.

Start with 14 days free. After that you only pay per active daemon — no platform fee, no surprises.

Free Trial

14 daysfree

Full feature set, zero risk.

  • All Pro features for 14 days
  • Protected in under a minute
  • Rolls into Pro seamlessly
Try 14 days free

Enterprise

On request

Maximum control & data sovereignty.

  • Everything in Pro
  • Local threat-detection LLM (on-prem)
  • Super-high-privacy mode soon
  • Advanced deployment settings
  • Custom threat levels
  • SSO, SLA, priority support & onboarding
Contact sales