Bulk Write Spike to Vector DB/RAG Knowledge Store (Memory Poisoning)

Detects abnormal bulk API operations (upsert, batch updates, or deletions) targeting vector database or Retrieval-Augmented Generation (RAG) knowledge stores. This activity is flagged when performed by non-authorized service identities or when ingestion volume exceeds a specific threshold within a short timeframe, potentially indicating an attempt to poison the agent's memory store or retrieval corpus to facilitate indirect prompt injection.