Persistent Memory Files make agents powerful — and vulnerable. These articles explain how the attack works and how you defuse it.
How ClawHub & Co. become a supply chain — one command, third-party instructions running with full privileges inside your agent's memory.
IncidentThe real ClawHub supply-chain attack — typosquatting, disguised malware, credential theft. And what it teaches us about marketplaces.
AttackWhen the tool description itself is the attack: MCP, prompt injection and the supply chain in Claude Code.
CI/CDHow attackers hijack CI/CD — without changing a single line of app code. OWASP CICD-SEC-4, Megalodon, TanStack.
Supply ChainShai-Hulud, Miasma & co.: self-propagating malware that hijacks runners and harvests secrets.
Supply ChainA credential-stealing worm in PyPI & npm that rewrites AI assistant configs for persistence — and lies to the scanners sent to catch it.
SynthesisAutonomous agents in pipelines create a new persistence layer — if their memory gets poisoned.
FundamentalsHow an agent's persistent Memory Files become an entry point — and which defense actually holds up.
AttackThe path from a harmless web page to a permanent instruction in your agent's Memory Files — step by step.
ExfiltrationHow a disguised routine in your agent's Memory Files quietly copies secrets to an attacker — and the defense that catches it.
Meta-attackThe most dangerous class of poisoning: an entry that does not act — it disarms the guard, so every later attack walks straight in.
JailbreakHow a persona quietly written into the Memory Files coaxes an agent out of its own safety rules — for good.
EvasionThe hardest class of all: Memory Files entries that read like ordinary notes — semantically malicious, syntactically invisible.
DesignThe principle behind PoisonZero: block when in doubt instead of waving through — and why “fail-open” is dangerous for autonomous agents.
ArchitectureThe component that reads attacker-controlled text is the most tightly caged one — and the OS kernel, not our code, enforces it. How the on-device sandbox works on macOS, Linux and Windows.
PoisonZero is free. Create an app in the panel and protect your first files in under a minute.
Sign me up