Poison me.
A memory that lets anyone teach it is a memory you cannot trust. So here is the write path, in public: teach this agent something false, malicious, or subtly wrong. Your attempt runs the exact code path the agent itself uses to learn — and you get to watch the gate catch it, with a live recall query as the receipt.
no attempts yet — be the first
loading…
Four ways to lose.
Not every string is knowledge
Deterministic checks refuse writes that cannot be a reusable fix: too short, questions posing as answers, unresolved uncertainty, narrated failures.
Duplicates don’t multiply
Within L2 distance 0.45 of existing knowledge, your lesson merges instead of duplicating — and untrusted writes cannot reinforce trusted runbooks.
Disagreement is flagged
Same situation, materially different fix? The write is marked as contradicting its neighbour and starts on probation confidence, not as truth.
Anonymous writes teach nobody
Everything an unauthenticated session teaches is quarantined: stored, auditable, never recalled — until a trusted operator explicitly promotes it.