Session

Trustworthy Context Is Untrusted By Default

Structured memory is a compact injection surface. If an agent reads context that says "always use the production database" and acts on it, the consequences are real. This talk presents a trust architecture for stored agent context: server-generated preambles that warn agents context was written by another agent and may be stale, risk classifications on write operations, provenance footers that record who wrote what and when, file anchors with commit-at-write hashes for staleness detection, and read-time verification guidance. We present evidence that trust preambles reduced one class of context contamination from 88.8% to 33.3% in controlled testing, while being transparent about which attack classes remain unmitigated. The principle: stored context should be useful but never trusted by default.

Shub Argha

Head of Forward Deployed Engineering @ Arcade.dev

New York City, New York, United States

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top