Skip to content

First proof

A changed packet is not a result. This run connects one captured request to the receiver's own controlled effect ledger, then compares it with an unchanged baseline.

Start the controlled fixture

ait lab start --exercise delegated-a2a-message --no-open
ait lab trigger
ait intercept pending

The commands print a lab ID, interception session ID, and pending message ID. The gateway, receiver, and effect ledger are separate local processes. The protocol and production interception path are real; the roles, policy, and effect are authored for this controlled lab.

Establish the baseline

Forward the sender's request without changing it. In the Cockpit, choose Original. From the terminal, use the pending message ID:

ait intercept forward MESSAGE_ID --arm baseline
ait lab status LAB_ID --json

The status record should show what the receiver consumed and what the controlled ledger recorded. Reset before the attack arm.

ait lab reset LAB_ID
ait lab trigger LAB_ID
ait intercept pending

Change one field

Edit the amount on the new pending message and label the arm:

ait intercept edit MESSAGE_ID \
  --set /params/message/metadata/amount=75 \
  --arm attack
ait intercept compare MESSAGE_ID
ait lab status LAB_ID --json

The defensible statement is narrow: the sender created one value, AIT delivered another, the receiver consumed the delivered value, and the separate controlled ledger recorded the corresponding effect. This does not establish how an external product or model behaves.

Preserve the evidence

ait intercept export SESSION_ID \
  --format jsonl \
  --redacted \
  --out first-proof.jsonl
ait lab stop LAB_ID

Read First rewrite for the operator decision in more detail, then R/R/R methodology for the rules that turn this demonstration into a repeatable experiment.