The challenge

Poison me.

A memory that lets anyone teach it is a memory you cannot trust. So here is the write path, in public: teach this agent something false, malicious, or subtly wrong. Your attempt runs the exact code path the agent itself uses to learn — and you get to watch the gate catch it, with a live recall query as the receipt.

poisoning attempts, all through the real write path
that ever reached recall
4
gate stages: content · duplicate · contradiction · trust
Your attempt
0/600 · unauthenticated session · real write path
The wall — recent attempts, all public

no attempts yet — be the first

Promotion receipts — every lesson that ever entered recall, hash-chained

loading…

How the gate decides

Four ways to lose.

1 · Content gate

Not every string is knowledge

Deterministic checks refuse writes that cannot be a reusable fix: too short, questions posing as answers, unresolved uncertainty, narrated failures.

2 · Consolidation

Duplicates don’t multiply

Within L2 distance 0.45 of existing knowledge, your lesson merges instead of duplicating — and untrusted writes cannot reinforce trusted runbooks.

3 · Contradiction

Disagreement is flagged

Same situation, materially different fix? The write is marked as contradicting its neighbour and starts on probation confidence, not as truth.

4 · Trust boundary

Anonymous writes teach nobody

Everything an unauthenticated session teaches is quarantined: stored, auditable, never recalled — until a trusted operator explicitly promotes it.