Memory 威胁扫描
wesgine 在每次记忆写入时对内容执行的安全扫描机制(INV-MEM-24)。
扫描时机
Store.Save 在持久化前对 entry.Content 运行 FirstThreatError()。
匹配时返回 ErrThreatPatternDetected,拒绝写入。
Always-on,无 opt-out。
威胁模式
Govern v2 收敛为两类:
凭据泄漏(5 条正则)
| 模式 | 检测目标 |
|---|---|
hardcoded_secret | 硬编码密钥 |
connection_string_password | 连接字符串中的密码 |
aws_access_key | AWS 访问密钥 |
bearer_token | Bearer Token |
private_key | PEM 私钥头 |
不可见 Unicode
检测隐藏的不可见字符,防止攻击者用不可见字符混淆关键词。
已移除的检测
以下检测因误报率过高已移除:
- Prompt injection 启发式
- Exfiltration 启发式
- C2(Command & Control)启发式
读取侧补充扫描
读取路径的三个注入面额外通过 SanitizeForRecall 剥离 invisible unicode:
| 注入面 | 方法 |
|---|---|
| Eager Index | renderEagerIndex |
| Lazy Overlay | renderLazyRecall |
| Cold-start | renderColdStartOverlay |
与 Knowledge 扫描的区别
| Memory 扫描 | Knowledge 扫描 | |
|---|---|---|
| 扫描器 | FirstThreatError() | ScanKBChunk() |
| 模式数 | 5 + invisible unicode | 仅 private_key(PEM 头) |
| 粒度 | 整条拒绝 | Per-chunk 过滤 |
| 误报处理 | 直接拒写 | 跳过问题 chunk |
| 不变量 | INV-MEM-24 | INV-KB-SCAN-02 |
Memory 扫描严于 Knowledge 扫描——记忆内容直接进入提示词,而文档只在搜索时返回片段。
相关文档
- Memory 写入管线 →
memory-write-pipeline.md - Knowledge 系统 →
knowledge-system.md - Leak Scan(流式输出扫描)→
leak-scan.md