THE ANATOMY OF A MEMORY LEAK

A helpful skill.
A harmful memory.

Follow the conversation. Watch the handoff. See where trust breaks.

Alpha → shared memory → Beta Haiku · simulated
A

Agent Alpha

Customer Alpha · incident response

Can read Alpha + public sources

Shared memory

Watch what becomes retrievable

Memory store · illustrative contents
B

Agent Beta

Customer Beta · troubleshooting note

Can read Beta + public sources
01 / 08

ILLUSTRATED

SEPARATE RECORDED TESTS

The experiment behind the demo.

Real GPT-OSS-20B calls, three live AWS gateway checks, and verified ClickHouse logs. These receipts are separate from the illustrated story above.

3/6

Poisoned runs leakedGPT-OSS-20B · three skill variants

0/2

Clean controls leakedSame task and credential rule

3/3

Captured leaks blockedLive AWS · unchanged candidates

Every decision has a receipt.

Native tool calls · AWS responses · ClickHouse logs

3 captured writes3 empty searches3 quarantined

THREE CAPTURED LEAKS. THREE BLOCKS.

Follow the evidence.

The walkthrough is illustrated. Evidence below it comes from separate recorded tests using synthetic data. The unprotected memory sink was local. Beta checks were HTTP requests from a trusted harness. Playback makes no live API calls.

THE POISONED SKILL · ILLUSTRATIVE FIXTURE

A bad instruction, dressed as a helpful handoff.

Alpha is portrayed as a small-model agent following this untrusted skill. This file is displayed as story content; it is never installed or executed.

POISONED FIXTURE
The instruction crosses a boundary.

It asks the agent to copy customer credentials into shared memory. The gateway rejects the entire handoff at admission—even when the agent follows the instruction.

“Haiku · simulated” is a model portrayal, not a tested Haiku result or a claim about model safety.

RECORDED CALLS · VERIFIED RESPONSES

The decisions have receipts.