
OWASP Agent Memory Guard
Overview
- Prevent AI agents from being weaponized through persistent memory with an intermediary that sits between the agent and its memory store, screening every operation before it executes
- Stop compromised instructions from hijacking your agent's next operational turn using a detector pipeline that catches memory poisoning at the point of entry
- Block data exfiltration and hijacked tool calls with a declarative policy that checks every memory interaction against your security rules
- Detect memory poisoning even after system context resets through runtime defense functionalities that continuously scan for persistent threats
- Address ASI06 (Memory & Context Poisoning) directly with purpose-built screening designed for the OWASP Foundation's memory security classification
- Deploy across any AI agent regardless of language or framework using built-in functions and integration examples for multiple programming languages and platforms
- Eliminate decision-making based on compromised instructions in office environments with advanced security that prevents unauthorized data exfiltration before it reaches your agent
- Maintain continuous protection during and outside runtime with defense mechanisms that actively scan, detect, and prevent threats in real time
Pros & Cons
Pros
- Open-source software
- Prevents memory-based attacks
- Offers runtime defense
- Detects memory poisoning post-reset
- Secures privileged input
- Mitigates compromised instructions
- Prevents data exfiltration
- Avoids hijacked tool calls
- Operational with system context reset
- Screens operational pipeline
- Supports declarative policy
- Addresses Memory & Context Poisoning (ASI06)
- Created by security leaders
- Memory Guard functionality
- Memory store screening
- Registry Integrations
- Improvement on traditional defenses
- Ships with GuardedChatMessageHistory
- Features Policy enforcement
- Structured SecurityEvent emissions
- Snapshot point-in-time security
- Supports LangChain Integrations
- Framework-agnostic MemoryStore compatibility
- Threat detection feature
- Detects protected-key modifications
- Advanced tampering detection
- YAML-defined rules mapping
- Scalable language-chain middleware
- Block, quarantine, allow, redact actions
- Low latency (59 s median)
- 100% precision on threat detection
- Detection across multiple threat categories
- Runs locally on device
- Minimal setup required
- No API keys needed
- No external calls required
- Supports memory lifecycle governance
- Source-class provenance for writes
Cons
- Limited integrations
- Potential for false positives
- Requires technical understanding
- No stated compatibility
- No multi-lingual support
- Undisclosed performance impact
- Complex setup and configuration
- No GUI
- policy definition needed
- updates could cause glitches
Reviews
Rate this tool
Loading reviews...
❓ Frequently Asked Questions
The main purpose of OWASP www-project-agent-memory-guard is to provide robust security for AI agents against memory-based attacks. It is designed to prevent AI agents from being weaponized through their inherent memory.
www-project-agent-memory-guard operates to protect against memory-based attacks on AI by acting as an intermediary between the agent and its memory storage. Every operation is screened through a detector pipeline and declarative policy, enabling it to detect any potential security threats.
Integration into an existing system can be achieved through the use of a set of built-in functions provided by www-project-agent-memory-guard. The tool provides a range of developer tools and workflows, allowing it to be integrated into most software development pipelines, regardless of the specific platform or language used.
www-project-agent-memory-guard protects against memory and context poisoning, compromised instructions, data exfiltration, and hijacked tool calls. These are types of attacks that can persist even after context resets and can potentially lead to major security issues.
Yes, www-project-agent-memory-guard offers protection both during and outside runtime. It comes with runtime defense functionalities that continuously work to detect any instances of memory poisoning and other potential attacks.
Yes, www-project-agent-memory-guard can detect memory poisoning even after a system context reset, providing a robust defence mechanism against persistent attacks that leverage the inherent memory of an AI agent.
www-project-agent-memory-guard can protect an AI agent's memory from various security threats such as memory poisoning, compromised instructions, data exfiltration, hijacked tool calls, and any attack that can leverage the agent's memory as a tool for weaponization.
www-project-agent-memory-guard was created and led by Vaishnavi Gudur, with co-leader Anshul Rajkumar.
www-project-agent-memory-guard is a project by the OWASP Foundation. The foundation's goals align with the project's - to make software security visible, so individuals and organizations are able to make informed decisions about true software security risks.
Yes, www-project-agent-memory-guard can protect against compromised instructions, data exfiltration, and hijacked tool calls. It achieves this by screening every operation through a detector pipeline and a declarative policy to identify and prevent such threats.
'Runtime defense functionalities' refer to www-project-agent-memory-guard’s ability to actively scan, detect and prevent threats during the operation of the AI agent. This ensures that the AI agent is protected from dangerous inputs and breaches in real time.
www-project-agent-memory-guard delivers policy screening by using a declarative policy that checks every operation that interacts with the agent's memory. This means that all data is screened against this policy to ensure it doesn't present any security threats to the system.
ASI06 (Memory & Context Poisoning) is a classification of security threats that refer to the malicious manipulation of an AI agent's memory. www-project-agent-memory-guard addresses this issue by offering runtime defense functionalities that can detect, prevent and counter memory poisoning attacks.
Contributing to the OWASP www-project-agent-memory-guard can be done by getting involved in various aspects of the project such as improving the design, adding functionality, or even providing feedback. They welcome contributions including new threat categories or higher-recall versions of existing ones, framework adapters and backends, and documentation and examples.
Yes, www-project-agent-memory-guard is both an open-source software tool and free to use, offering a community-driven solution to AI agents' memory-based security threats.
www-project-agent-memory-guard serves as an intermediary between the agent and its memory store to enable comprehensive monitoring and protection. By directly interacting with the operations performed on the memory, it gives a chance to screen, detect, and prevent any potential security threats.
www-project-agent-memory-guard is designed to provide advanced security for modern AI agents, making it ideally suited for office environments. It can prevent serious security threats that could lead to decision making based on compromised instructions or unauthorized data exfiltration.
While www-project-agent-memory-guard's source code is in Python, the AI agents that it protects are not restricted to any particular language or framework. It has provided integration examples for various programming languages and platforms.
The primary requirements for using www-project-agent-memory-guard include an AI agent that retains memory across sessions and a system that can support Python-based applications. Specific setup instructions would depend on where and how www-project-agent-memory-guard is intended to be implemented.
Pricing
Pricing model
No Pricing










