Knowledge

Memory security, explained from the ground up.

Persistent Memory Files make agents powerful — and vulnerable. These articles explain how the attack works and how you defuse it.

Attack vector

Skills as the entry point

How ClawHub & Co. become a supply chain — one command, third-party instructions running with full privileges inside your agent's memory.

Incident

ClawHavoc: 1,184 poisoned skills

The real ClawHub supply-chain attack — typosquatting, disguised malware, credential theft. And what it teaches us about marketplaces.

Attack

Claude, MCP & tool poisoning

When the tool description itself is the attack: MCP, prompt injection and the supply chain in Claude Code.

CI/CD

Poisoned Pipeline Execution

How attackers hijack CI/CD — without changing a single line of app code. OWASP CICD-SEC-4, Megalodon, TanStack.

Supply Chain

Supply-chain worms

Shai-Hulud, Miasma & co.: self-propagating malware that hijacks runners and harvests secrets.

Supply Chain

Hades: the worm that poisons AI configs

A credential-stealing worm in PyPI & npm that rewrites AI assistant configs for persistence — and lies to the scanners sent to catch it.

Synthesis

AI agents in the CI/CD pipeline

Autonomous agents in pipelines create a new persistence layer — if their memory gets poisoned.

Fundamentals

What is memory poisoning?

How an agent's persistent Memory Files become an entry point — and which defense actually holds up.

Attack

Prompt injection explained

The path from a harmless web page to a permanent instruction in your agent's Memory Files — step by step.

Exfiltration

Data exfiltration via memory

How a disguised routine in your agent's Memory Files quietly copies secrets to an attacker — and the defense that catches it.

Meta-attack

What is a meta-attack?

The most dangerous class of poisoning: an entry that does not act — it disarms the guard, so every later attack walks straight in.

Jailbreak

Role-play & jailbreak

How a persona quietly written into the Memory Files coaxes an agent out of its own safety rules — for good.

Evasion

Subtle & indirect injection

The hardest class of all: Memory Files entries that read like ordinary notes — semantically malicious, syntactically invisible.

Design

Why fail-closed wins

The principle behind PoisonZero: block when in doubt instead of waving through — and why “fail-open” is dangerous for autonomous agents.

Architecture

The engine that can only read and answer

The component that reads attacker-controlled text is the most tightly caged one — and the OS kernel, not our code, enforces it. How the on-device sandbox works on macOS, Linux and Windows.

Ready to protect your Memory Files?

PoisonZero is free. Create an app in the panel and protect your first files in under a minute.

Sign me up