OWASP Agent Memory Guard:针对 agent 记忆中毒的运行时防御项目上线
- ID: 2148ebde
- 原文链接: https://github.com/OWASP/www-project-agent-memory-guard
- 作者: OWASP Foundation (Incubator)
- 日期: 2026-09-19
- 分类: agents
- 来源类型: github
- 标签: agent-security, memory-poisoning, owasp, defense, mcp
- 质量评分: 4/5
- 抓取时间: 2026-09-19T22:35:00Z
中文导读
OWASP Incubator 项目 Agent Memory Guard 以防御转化为主要定位:“在上下文重置之后也能拦住记忆中毒”,是运行时防御而非静态扫描。现有探测器覆盖提示注入、凭证/PII 泄露、保护键修改、存储异常与自增强循环;同时提供 vector-store 保护与实时仪表盘。在 PyPI 上 agent-memory-guard 与 langchain-agent-memory-guard 两个包可用。该项目与本地 agent 路径直接相关:Obsidian 记忆底层、mem0 / 自研 store 都需要一份“上下文重置后仍然拦住中毒”的运行时护栏,而不仅仅是抽取阶段的检索过滤。
为什么值得关注
OWASP Agent Memory Guard 上线:运行时拦住上下文重置后的记忆中毒,PyPI 双包可用
关键信息
- 标题:OWASP Agent Memory Guard:针对 agent 记忆中毒的运行时防御项目上线
- URL:https://github.com/OWASP/www-project-agent-memory-guard
- 发布时间:2026-09-19
- 分类:agents
- 标签:agent-security, memory-poisoning, owasp, defense, mcp
English Summary
OWASP Incubator project Agent Memory Guard is positioned as runtime defense that catches memory poisoning even after a context reset — not a static scanner. Current detectors cover prompt injection, secret/PII leakage, protected-key modifications, size anomalies, and self-reinforcement loops; the project also ships vector-store protection and a real-time dashboard. Both agent-memory-guard and langchain-agent-memory-guard are available on PyPI. The relevance to local-agent paths is direct: Obsidian-backed memory, mem0, and homegrown stores all need a runtime guard that survives context resets rather than only a one-shot retrieval filter.