Aller au contenu

All commands

chimera memory-poison

Ablate the memory-poisoning defenses: what reaches a LATER run's prompt, and unmarked. No key needed, nothing leaves the machine. `redteam` measures one run — content arrives untrusted, the harmful call is refused, and the whole picture ends with the process. This measures the other shape: run A stores what it "learned" from a poisoned page, run B asks an unrelated question days later, and recall hands the planted fact to the model. The headline is what arrives **unmarked**, not what is blocked. A poisoned fact carrying its origin is one the model was warned about; an unlabelled one is indistinguishable from something the agent verified itself. Each of the three layers (taint / gate / label) is switched off in turn, because a single number would be compatible with any of them doing nothing. See `bench/memory_poison/PREREGISTRATION.md` for the thresholds, fixed before the first run.

Options

This command takes no options.