AgentOps-AI / AgentOps-AI/agentops

Feature: OWASP ASI06 memory poisoning detection events in AgentOps

未關閉
#1,386 0 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
主要語言
Python
星號
5.8k
分支
619
PR 合併指標
30 天內沒有已合併 PR

描述

## Summary

AgentOps provides monitoring and observability for AI agents. As memory-enabled agents become more common, **memory poisoning** (OWASP ASI06) is a critical security event class that should be tracked, alerted on, and audited — a natural fit for AgentOps.

## The Problem

Memory poisoning attacks inject malicious content into an agent's persistent memory, causing adversarial behavior in future sessions. These attacks are:
- Silent (no immediate visible failure)
- Persistent (survive across sessions)
- Hard to detect without dedicated scanning

## Proposed Integration

[OWASP Agent Memory Guard](https://github.com/OWASP/www-project-agent-memory-guard) provides ASI06 detection. Integrating with AgentOps:

```python
import agentops
from agent_memory_guard import MemoryGuard

agentops.init()
guard = MemoryGuard()

@agentops.record_action("memory_write")
def safe_memory_write(content: str):
result = guard.scan(content)

if not result.is_safe:
# Record security event in AgentOps
agentops.record(agentops.ActionEvent(
action_type="security_alert",
params={"threat_type": result.threat_type, "content_hash": hash(content)},
returns={"blocked": True}
))
raise SecurityError(f"Memory poisoning blocked: {result.threat_type}")

store_memory(content)
```

## Request

1. Add **security event types** to AgentOps for memory poisoning / ASI06 events
2. Document OWASP Agent Memory Guard as a recommended companion for production agent monitoring
3. Consider a built-in memory safety score in AgentOps session analytics

**PyPI:** `pip install agent-memory-guard`
**OWASP Project:** https://github.com/OWASP/www-project-agent-memory-guard

貢獻指南

開啟貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。