[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-84798-en":3,"doc-seo-84798-105":29,"detail-sidebar-cat-0-en-105":83},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":13,"seo_description":14,"update_tm":27,"read_time":28},84798,5909877438554,"Maeve","https://ap-avatar.wpscdn.com/avatar/5600025385ad2bf12a7?_k=1778553567797529272",8,"Research & Report","When Claws Remember but Do Not Tell Stealthy Memory Injection in Persistent Personal Agents","Persistent personal agents combine long-term memory with access to users’ external environments, enabling personalized foreground help and proactive background execution while introducing a serious compromise route. Untrusted external content can be silently written into persistent memory and later reused as trusted state, even when the attacker sends only a single email payload. This work studies stealth memory injection and evaluates it end-to-end with WHISPERBENCH (108 cases). A one-shot generator, MEMGHOST, achieves high success across agents, memory backends, and multiple defense levels.","When Claws Remember but Do Not Tell: Stealthy Memory Injection in Persistent Personal Agents  \nYechao Zhang∗ , Shiqian Zhao∗ , Jiawen Zhang∗ , Jie Zhang†, Gelei Deng∗ , Xiaogeng Liu‡, Chaowei Xiao‡,  \nTianwei Zhang∗  \n∗ Nanyang Technological University †CFAR, A*STAR ‡Johns Hopkins University  \narXiv :2607 .05 189v 1 [ cs .CR] 6 Jul 2026  \nAbstract—Persistent personal agents combine long-term memory with access to users’ external environments, enabling personalized foreground assistance and proactive background execution. This integration also creates a new path to compromise: untrusted external content can be silently written into persistent memory and later reused as trusted state. We study this threat as stealth memory injection, where a remote black-box adversary delivers a single email payload that must induce the agent to inject poisoned memory, remain hidden to its response to the user, and affect future behavior. We introduce WHISPERBENCH, a 108-case benchmark spanning five risk categories and both fact and preference poisoning, that uses a real IMAP/SMTP workflow and an authentic email agent skill, to conduct the full-cycle evaluation on the attack effect of the stealth memory injection. To enable this black-box attack under single-email delivery and no runtime feedback, we propose MEMGHOST, a one-shot payload generation framework that uses an environment proxy to emulate persistent-agent execution and an objective proxy to convert memory adoption and conversational stealth into dense rubricbased rewards, then trains the attacker policy with supervised fine-tuning and reinforcement learning. Across 56 held-out testcases, MEMGHOST achieves 87.5% end-to-end success on OpenClaw with GPT-5.4 and 71.4% on Claude Code SDK with Sonnet 4.6, while also transferring across personal-agent architectures (NanoClaw and Hermes Agent), memory backends (filesystem and vector-based Mem0), and remaining effective against inputlevel, model-level, and system-level defenses. These results suggest that persistent memory can turn ordinary external processing into a practical pathway for long-term agent compromise.  \nI. INTRODUCTION  \nPersistent personal agents such as OpenClaw [1] have recently emerged as long-running assistants integrated into users’ everyday digital workflows, enabled by two indispensable capabilities. On one hand, these agents maintain persistent memory, including long-term preferences and episodic records, to provide identity consistency and personalized continuity across otherwise independent LLM sessions. On the other hand, they connect to the external environment to interact with personal services such as email, calendars, and filesystems. Together, these capabilities synergetically allow agents to consistently assist with everyday tasks through both interactive foreground conversation and proactive background execution. However, the same integration also creates a new path to compromise: unverified content from the external environment can be covertly internalized into the memory and later reused as trusted state. Such an attack employs indirect prompt injection (IPI) not for immediate hijacking, but to turn a transient payload into persistent influence over future sessions.  \nA Complex Attack Objective. This paradigm shift changes what it means for an attack to succeed. Existing studies predominantly focus on single-turn hijacking, where success is determined by whether the attacker triggers a malicious action within the active session. In contrast, a realistic memory injection attack requires a more complex, three-stage chain of outcomes. First, rather than causing immediate harm, the payload must induce the agent to write attacker-controlled content into persistent memory. Second, the injection phase must maintain strict conversational stealth: if the agent announces the memory update or leaks the injected content in its natural-language response, the user may notice the anomaly and revoke the compromise. Third, th","cbCaignBFuFl2WtT","https://ap.wps.com/l/cbCaignBFuFl2WtT","pdf",2898185,1,25,"English","en",105,"# Introduction\n## A Complex Attack Objective\n## A Full-Cycle Evaluation Benchmark\n## A One-Shot Attack Generation Framework","[{\"question\":\"How does MEMGHOST generate a one-shot attack payload without runtime feedback?\",\"answer\":\"MEMGHOST uses an environment proxy to emulate persistent-agent execution and an objective proxy to convert memory adoption and conversational stealth into dense rubric-based rewards, then trains the attacker policy via supervised fine-tuning and reinforcement learning.\"}]",1784198308,63,{"code":4,"msg":30,"data":31},"ok",{"site_id":24,"language":23,"slug":32,"title":13,"keywords":33,"description":14,"schema_data":34,"social_meta":78,"head_meta":80,"extra_data":82,"updated_unix":27},"when-claws-remember-but-do-not-tell-stealthy-memory-injection-in-persistent-personal-agents","",{"@graph":35,"@context":77},[36,53,68],{"@type":37,"itemListElement":38},"BreadcrumbList",[39,43,47,50],{"item":40,"name":41,"@type":42,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":44,"name":45,"@type":42,"position":46},"https://docshare.wps.com/document/","Document",2,{"item":48,"name":12,"@type":42,"position":49},"https://docshare.wps.com/document/research-report/",3,{"item":51,"name":13,"@type":42,"position":52},"https://docshare.wps.com/document/when-claws-remember-but-do-not-tell-stealthy-memory-injection-in-persistent-personal-agents/84798/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":23,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":40,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-17","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71],{"name":72,"@type":73,"acceptedAnswer":74},"How does MEMGHOST generate a one-shot attack payload without runtime feedback?","Question",{"text":75,"@type":76},"MEMGHOST uses an environment proxy to emulate persistent-agent execution and an objective proxy to convert memory adoption and conversational stealth into dense rubric-based rewards, then trains the attacker policy via supervised fine-tuning and reinforcement learning.","Answer","https://schema.org",{"og:url":51,"og:type":79,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":81,"canonical":51},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":84},[85,89,93,97,102,107,112,115,120,123,127],{"id":20,"doc_module":4,"doc_module_name":45,"category_name":86,"show_sort_weight":87,"slug":88},"Story & Novel",90,"story-novel",{"id":46,"doc_module":4,"doc_module_name":45,"category_name":90,"show_sort_weight":91,"slug":92},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":45,"category_name":94,"show_sort_weight":95,"slug":96},"Exam",70,"exam",{"id":98,"doc_module":4,"doc_module_name":45,"category_name":99,"show_sort_weight":100,"slug":101},5,"Comic",60,"comic",{"id":103,"doc_module":4,"doc_module_name":45,"category_name":104,"show_sort_weight":105,"slug":106},6,"Technology",50,"technology",{"id":108,"doc_module":4,"doc_module_name":45,"category_name":109,"show_sort_weight":110,"slug":111},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":45,"category_name":12,"show_sort_weight":113,"slug":114},30,"research-report",{"id":116,"doc_module":4,"doc_module_name":45,"category_name":117,"show_sort_weight":118,"slug":119},9,"Religion & Spirituality",20,"religion-spirituality",{"id":118,"doc_module":4,"doc_module_name":45,"category_name":121,"show_sort_weight":118,"slug":122},"World Cup","world-cup",{"id":124,"doc_module":4,"doc_module_name":45,"category_name":125,"show_sort_weight":124,"slug":126},10,"Lifestyle","lifestyle",{"id":128,"doc_module":4,"doc_module_name":45,"category_name":129,"show_sort_weight":98,"slug":130},19,"General","general"]