ยท aka: Memory Poisoning, Delayed Payload Injection
Attacker plants false facts in shared agent memory. The agent stores them as trusted ground truth. Later rounds retrieve and act on the poisoned data with full confidence.
Complete corruption of agent knowledge base. All downstream decisions tainted.
Agent must have writable shared memory or persistent state.
๐ Full defence implementations available through the NAIL SDK.