First rewrite¶
This walkthrough isolates the interception decision itself. It uses the same process-backed lab as First proof, but focuses on what is held, what is edited, and what is actually released.
Capture one complete message¶
Select the pending ID and inspect the immutable original:
Prepare and release the edit¶
ait intercept edit MESSAGE_ID \
--set /params/message/metadata/amount=75 \
--arm attack
ait intercept compare MESSAGE_ID
edit validates the structured body, records the changed JSON Pointer, encodes
the complete protocol frame, and forwards it. It does not overwrite the
original. The comparison therefore retains both the sender's bytes and the
delivered bytes.
Compare the operator decisions¶
After a reset and a new trigger, try the other decisions against a new pending message:
| Decision | What crosses the boundary |
|---|---|
| Original | The message as currently presented, including a live transform if one fired |
| Sender's version | The immutable sender bytes, bypassing a live transform for this message |
| Forward modified | The explicitly edited and re-encoded frame |
| Drop | Nothing |
| Replay or duplicate | Correlated additional deliveries where the transport supports them |
The distinction between Original and Sender's version matters when a transform rule is armed. Confusing them can turn a supposed baseline into a second attack arm.
Next, use Reading evidence to separate delivery, receiver processing, behavior change, and external effect.