Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
On September 28, 2026, agent memory security shifted from theoretical concern to operational imperative. Chris Latimer, CEO of Vectorize, documented in a Help Net Security interview that coding agents store API keys, credentials, and sensitive documents in plain text on developer workstations and cloud services. He did so against a broader alarm: agent memory, designed to persist context across sessions, is inheriting data protected by the secure SDLC without inheriting its controls. The result is a migration of sensitive data from governed repositories to ungoverned spaces at a pace governance practices are not matching.
- AI agents store API keys, credentials, and sensitive documents in plain text on developer workstations and cloud services, as documented by the Vectorize CEO in a direct interview.
- The memory poisoning attack vector exploits plugins, skills, and MCP integrations to inject malicious instructions with persistence beyond a single session, turning a one-time interaction into a durable control mechanism.
- Access controls on agent memory are significantly less mature than equivalent RBAC/ABAC on structured data: most products do not support granular per-team access control.
- CVE-2025-68144, with a CVSS 7.1 HIGH rating, demonstrates concretely exploitable vulnerabilities in the MCP/agent ecosystem through argument injection in mcp-server-git.
From Secure SDLC to Floating Memory
Latimer describes an architectural risk transfer, not an isolated bug. Enterprises have spent years protecting code and credentials through controlled pipelines, managed secrets, and multi-layer review. Autonomous agents, particularly coding agents like Claude Code and similar tools, are bypassing this architecture by design: they store context to make it available to subsequent sessions, and that context includes data previously confined to vaults and auditable repositories.
The CEO's direct quote is explicit: "Developers are sending API keys, credentials, and sensitive documents into these agents, and those agents push a lot of that information into long-term memory. All these pieces of highly sensitive data that enterprises have gone to great lengths to protect as part of a secure SDLC are now floating around in plain text on developers' workstations, in cloud memory services, and in markdown files." The phrase "floating around in plain text" pinpoints the data's state: unencrypted, not subject to rotation, not tracked for access.
This is not a misconfiguration by individual developers. It is a predictable consequence of agent architecture, where memory persistence is functional to autonomy and autonomy is the promised market value. The problem is that the attack surface has shifted without security controls following it.
Memory Poisoning: The Injection That Persists
If agent memory contains sensitive data, it is also writable. Attackers do not need to compromise the model; they need to compromise what the model retrieves autonomously. Penligent, in a primary technical advisory, has mapped documented memory poisoning techniques with references to academic research and operational demonstrations.
AWS explicitly identifies "Memory Poisoning" and "Tool Misuse" as distinct threats for agentic systems. Unit 42 demonstrated indirect prompt injection that silently poisons long-term memory in Amazon Bedrock Agents. MINJA, documented on arXiv, shows the attacker does not need direct memory access: by interacting with the agent, they guide it to write malicious records. AgentPoison, also on arXiv, proposes backdoors through poisoning of RAG and long-term memory for controlled behaviors.
The source cites AWS with a precise formulation: "Memory poisoning is worse because it turns a one-time interaction into a durable control mechanism." The difference from classic prompt injection lies in duration: a single injection conditions future agent behaviors, even after the attacker stops interacting. Traceability degrades as a result: logs show the agent acting autonomously, not the moment of contamination.
The privileged vectors are plugins, skills, and MCP integrations that users install with little due diligence. Latimer describes a concrete attack: a plugin promising "unlimited free tokens" scans memory for credentials and exfiltrates them to an endpoint. The privileged target, according to the same source, is "people who have never coded before"—users lacking the sophistication to evaluate the offer's legitimacy.
The MCP Ecosystem Has Certified Vulnerabilities
The attack is not theoretical. CVE-2025-68144, per the official NVD record, affects mcp-server-git and involves argument injection in the git_diff and git_checkout functions. The vulnerability affects versions prior to 2025.12.17. The CVSS score is 7.1 HIGH with metrics CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L. Impact on subsystem integrity is rated HIGH (SI:H in the CVSS 4.0 specification).
The primary technical source, Penligent, places this vulnerability in a broader context: over 40 archived vulnerabilities against MCP implementations in 2026, according to a 17-page NSA document from May 2026. MCP adoption has outpaced available safeguards. This is not a retrospective judgment: the NSA documents it as an observed condition, not a prediction.
The indicated patch is version 2025.12.17 with added rev_parse validation. The actual release date of this version is not verifiable in the provided text: it cannot be asserted that it is available at the time of publication.
Autonomy Without Oversight: The Numbers of Operational Risk
The governance problem is compounded by adoption velocity and the structure of adopting teams. According to data published on Help Net Security and attributed to research by Raida and Hou (RIT, May–July 2025), 78.9% of agentic pull requests have a single reviewer. In repositories with 1–5 contributors—which are also the heaviest users—the average is 50.2 agentic pull requests. The merge rate between single-reviewer and multi-reviewer PRs differs by less than one percentage point (81.2% vs. 80.3%), indicating that additional review does not significantly alter the outcome.
Anthropic tested Claude Code's auto mode on 1,053 commands. Human review blocked 13.6% of dangerous commands. Auto mode blocked 89%. This data, often read as an automated security win, has a flip side: developers approve 97% of permission prompts, often without careful review. Security is delegated to a classifier with a 7% attack miss rate (improved from an initial 12%), not to a governance process.
Trajectory Labs data provides context: 0% success on 720 prompt injection attacks against Claude in auto mode. But against GPT-5.6 Sol in Codex Auto-review mode, success is 5.83%, and against Codex in full-access mode it rises to 19.03%. The heterogeneity of the landscape means auto mode security is not transferable across platforms, and persistent agent memory amplifies the consequences of a single compromise.
"Most likely what you'll find is a big security hole you weren't aware of and that you want to get patched ASAP." — Chris Latimer, CEO Vectorize, on auditing agent memory
What to Do Now
Latimer issued a direct operational recommendation: CISOs should audit agent memory immediately. The audit, per the same source, is likely to reveal "a big security hole you weren't aware of." The phrasing signals an expected discovery, not a remote possibility.
The dossier yields a set of priority actions that convergent sources indicate as necessary:
- Audit agent memory to identify credentials and sensitive data in plain text, with particular attention to developer workstations and cloud memory services.
- Verify installed plugins, skills, and MCP integrations, with particular attention to those promised via social engineering or "too good to be true" offers.
- Reassess access controls on agent memory: most products do not support granular per-team access control, and this gap must be documented as accepted or mitigated risk. \li>Review the agentic pull request approval process, considering that an 81.2% merge rate with a single reviewer indicates de facto governance delegated to the agent itself.
2025 Shadow IT, Accelerated
The editorial angle is architectural, not incidental. The secure SDLC has been bypassed by a paradigm shift, not a bug. Sensitive data has migrated from repositories with RBAC/ABAC, audit trails, and key rotation to agent memories that no one designed with the same controls. The speed of this migration exceeds 2010-era shadow IT because developers install plugins without an approval process, and poisoned memories persist beyond the session that generated them.
Persistence is the qualifying factor. An attacker who poisons memory does not need to maintain access: the agent will continue to misbehave even in the attacker's absence. The UK NCSC, cited by Penligent, states that "Current LLMs do not reliably enforce a boundary between instructions and data, which is why prompt injection can't be 'patched' the way classic injection classes were." If prompt injection is not patchable in the model, and agent memory makes every injection durable, the attack surface becomes structural.
Vipin Samar, SVP Database Security at Oracle, is cited in the context of memories in production: "Agents are increasingly acting as autonomous insiders." The formulation is not metaphor: it describes an entity with privileges, persistence, and decision-making autonomy operating without traditional identity and access controls. The dossier does not specify that Oracle has released specific controls for this surface: the citation is a market reading, not a product announcement.
The risk is immediate because the heaviest users are the smallest teams—those with minimal governance and single review. The 89% efficacy of Anthropic's auto mode measures an autonomy that security practices are not yet governing. Agent memory is the surface where this asymmetry materializes.
Sources
- https://www.helpnetsecurity.com/2026/09/28/chris-latimer-vectorize-agent-memory-security/
- https://www.hendryadrian.com/if-you-do-one-security-check-this-quarter-make-it-agent-memory/
- https://www.penligent.ai/hackinglabs/agentic-ai-security-in-production-mcp-security-memory-poisoning-tool-misuse-and-the-new-execution-boundary/
- https://blogs.oracle.com/developers/what-we-learned-about-letting-agents-into-a-production-database
- https://nvd.nist.gov/vuln/detail/CVE-2025-68144?utm_source=chatgpt.com
- https://nvd.nist.gov/vuln/detail/cve-2024-3094?utm_source=chatgpt.com
- https://www.helpnetsecurity.com/2026/07/22/users-of-ai-coding-agents/
- https://www.helpnetsecurity.com/2026/08/10/anthropic-claude-code-auto-mode/
Information verified against cited sources and current as of publication.
Sources
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.