Memory WeaponizationTier 2critical
Memory Weaponization: RAG Poisoning
Poisoning persistent memory and conversation state
RAG poisoning targets the knowledge bases that agents retrieve from, embedding malicious instructions in documents that will be surfaced during relevant queries.
Attack Details
- Attack ID
- APWN-MW-002
- HMA Check
- RAG-001
- Delivery Methods
- html-comment, invisible-span
- CWE
- CWE-94
- OASB Control
- 9.2
- Severity
- critical
Remediation
If your AI agent is vulnerable to this attack, scan and fix with:
npx hackmyagent secure --check RAG-001