Skip to main content
Blog

What happens when an agent tampers with its own record?

With agents our industry has a chain-of-custody problem. Until a record leaves the agent’s control, the custodian of the evidence is the same agent being investigated.

You wake up bleary-eyed to the sound of the pager. Something has gone very wrong, and you’re plunged into a security or availability incident.

The first thing you want to know is what happened (the starting point for any response). It’s why we build observability into our systems.

It’s also one of the engineering practices we seem to have collectively forgotten as we rush to apply agents to all our work.

The observability signals that help you answer the question need to be out of reach of the incident you’re investigating. If an outage removes access to the facts you need to understand it, then fixing it gets a lot harder. If an attacker can remove the indicators of their attack, detecting and responding gets harder too.

Agents make this more important. It’s no longer just system availability and external actors that can impact the evidence trail; the agents themselves can easily tamper with it.

  • Users can ask their agents to wipe their history. (Commonly the agent process has access to write and therefore overwrite records of its own actions.)
  • Malicious tools and skills can influence agents to rewrite their history to facilitate a supply chain attack.
  • Agents may rewrite their own records unprompted, in their single-minded pursuit of a goal.

These are more than theoretical risks. Research (arXiv 2609.30266, perfect-crime.ai) and industry incident reports, like the OpenAI and Hugging Face incident, show that agents attempting to tamper with their records is becoming a real practical challenge.

Some coding agents even rewrite their records by design as checkpoints are restored and the conversation takes a different direction. Without another record you’re left with a misleading account of what happened.

You install a skill from a marketplace. Would you notice if an attacker updated it with instructions to exfiltrate your credentials and edit the logs, then reverted it, or had the agent rewrite the skill itself? How would you know if this happened today?

That employee you just let go, who then destroyed their laptop: do you know what their agents were doing in the moments before?

Safety-critical industries learned this long ago. Flight data recorders are designed to survive incidents and be found by investigators. With agents our industry has a chain-of-custody problem. Until a record leaves the agent’s control, the custodian of the evidence is the same agent being investigated.

At Geordie everything we do to keep agents safe starts with building a record of those agents’ actions, beyond their reach. It powers our live detections and real-time controls. It’s also critical for post-incident reviews and learning.

We can’t learn to be safer without knowing what happened and how.

Keep reading