In an interview with Help Net Security, Chris Latimer, CEO of Vectorize, describes a serious blind spot in AI agent security: agent memory. Latimer says he found coding agents storing API keys, credentials, and sensitive documents in plain text on developer workstations, in cloud memory services, and in markdown files. That data, he argues, bypasses the protections enterprises have built into their secure software development lifecycle.
Latimer identifies memory poisoning as a key attack vector. Malicious plugins, skills, and MCP integrations can be used to plant memories that change agent behavior, and attackers may target novice developers with offers that sound too good to be true. Once installed, such a plugin could scan agent memory for credentials and send them to an attacker-controlled endpoint.
He also notes that access control for agent memory is far less mature than traditional RBAC and ABAC controls for structured data. Most products lack fine-grained controls for team-based or graduated access. For CISOs, Latimer recommends at least an informal audit of agent memory solutions in production, expecting to find unvetted tools and large amounts of sensitive plain-text data ripe for exfiltration.