If we want to avoid making AI agents a huge new attack surface, we’ve got to treat agent memory the way we treat databases: ...