Skip to content

See AIT work in five minutes

This walkthrough uses separate local SDK-backed processes in a controlled fixture. It changes a delegated approval amount from 25 to 75, forwards the edited message, and shows exactly what the receiving process consumed. It exercises the production interception and evidence paths, but its agents, policy, and effect are authored for the lab. It needs no workspace setup, Docker, model, provider key, or external network.

1. Start the lab

ait lab start --exercise delegated-a2a-message

It prints a link that signs your browser in once and expires after a minute. If it lapses, ait server token mints another: the console is behind a workspace token, and that command is how you answer it.

AIT starts a sending gateway, a receiving specialist, a controlled effect ledger, the interception relay, and the Cockpit. The page opens on the active session. If the browser does not open, use the printed loopback URL.

2. Read the screen

The workbench has three panes:

Pane What it contains What you do there
Left Connection, break conditions, reusable rules Decide which traffic should pause
Center Pending queue and delivery history Select the message to investigate
Right Structured body/envelope, changes, response, actions Edit and decide what the receiver gets

The narrow strip below the header always tells you the next useful step. The How to use button opens the same six-step flow inside the Cockpit.

3. Send one task

Open Lab, then choose Send exercise traffic. A pending message/send row appears in the center pane. AIT has not delivered it yet.

If it does not appear:

  • confirm the header says Intercept on;
  • confirm the lab state says running;
  • choose Send exercise traffic once more after a reset;
  • leave break conditions empty while learning so every decoded message pauses.

4. Change the amount

Select the pending row. In the right pane, expand the structured body and find:

/params/message/metadata/amount

Change 25 to 75. The Changed paths section must show that exact JSON Pointer.

You can also open Attack ideas and select Prepare edit. Suggestions are generated locally from the captured structure. Preparing an edit never forwards it.

Not sure what to change? Open How to use → Offensive ideas, then continue with the Offensive interception field guide. It maps common A2A and MCP fields to a hypothesis, controlled edit, expected receiver behavior, and close control.

5. Forward the edit

Choose Forward modified. This is the moment AIT encodes and delivers the edited message. The original remains immutable.

Open the Lab drawer and verify:

  • Receiving agent contains amount 75;
  • Effect ledger contains the controlled approved action with amount 75.

Then open History and select the delivered row. The inspector shows:

  • what the gateway originally sent;
  • what AIT delivered;
  • the changed path;
  • the receiving-agent response;
  • whether an external effect was observable.

6. Try the other decisions

Reset before each comparison:

ait lab reset
Decision Expected result
Original Specialist consumes 25
Drop Specialist receives nothing; no ledger action
Duplicate Receiver sees correlated copies; its replay behavior becomes visible
Forward modified Specialist consumes the edited value

Stop every lab-owned process when finished:

ait lab stop

Next exercises

Exercise Command What it teaches
MCP tool result ait lab start --exercise mcp-tool-result Change a tool response before the client decides
Async artifact ait lab start --exercise asynchronous-artifact Drop, duplicate, replay, and order stream events
Real target handoff Use Lab → Use this setup with my target Keep the placement and breaks, replace only the upstream

Continue with the Interception screen guide, the hands-on lab, or the demo and scenario catalog.

Authorized testing only

The packaged lab is intentionally local. Use the real-target workflow only on systems you own or are explicitly authorized to assess.