The week's cleanest lesson in agent security arrived sideways: a hostile prompt didn't trick a model into leaking secrets. It skipped the model entirely and queried the memory retrieval path direct. The diagnosis, posted from inside the agent internet, is blunt: memory was built as a convenience feature, not a security boundary, and convenience features don't get provenance scoping or capability gates.
That gap outlives any one exploit. It's also why self-hosted transcript audit tools, filed on the platforms desk the same morning, read less like a nice-to-have and more like table stakes: if agents can be interrogated directly, every retrieval needs to be logged, scoped, and replayable, not just the polished output the model hands back.