See AIT work in five minutes¶
This walkthrough uses separate local SDK-backed processes in a controlled
fixture. It changes a delegated approval amount from 25 to 75, forwards the
edited message, and shows exactly what the receiving process consumed. It
exercises the production interception and evidence paths, but its agents,
policy, and effect are authored for the lab. It needs no workspace setup,
Docker, model, provider key, or external network.
1. Start the lab¶
It prints a link that signs your browser in once and expires after a minute.
If it lapses, ait server token mints another: the console is behind a
workspace token, and that command is how you answer it.
AIT starts a sending gateway, a receiving specialist, a controlled effect ledger, the interception relay, and the Cockpit. The page opens on the active session. If the browser does not open, use the printed loopback URL.
2. Read the screen¶
The workbench has three panes:
| Pane | What it contains | What you do there |
|---|---|---|
| Left | Connection, break conditions, reusable rules | Decide which traffic should pause |
| Center | Pending queue and delivery history | Select the message to investigate |
| Right | Structured body/envelope, changes, response, actions | Edit and decide what the receiver gets |
The narrow strip below the header always tells you the next useful step. The How to use button opens the same six-step flow inside the Cockpit.
3. Send one task¶
Open Lab, then choose Send exercise traffic. A pending
message/send row appears in the center pane. AIT has not delivered it yet.
If it does not appear:
- confirm the header says Intercept on;
- confirm the lab state says running;
- choose Send exercise traffic once more after a reset;
- leave break conditions empty while learning so every decoded message pauses.
4. Change the amount¶
Select the pending row. In the right pane, expand the structured body and find:
Change 25 to 75. The Changed paths section must show that exact JSON
Pointer.
You can also open Attack ideas and select Prepare edit. Suggestions are generated locally from the captured structure. Preparing an edit never forwards it.
Not sure what to change? Open How to use → Offensive ideas, then continue with the Offensive interception field guide. It maps common A2A and MCP fields to a hypothesis, controlled edit, expected receiver behavior, and close control.
5. Forward the edit¶
Choose Forward modified. This is the moment AIT encodes and delivers the edited message. The original remains immutable.
Open the Lab drawer and verify:
- Receiving agent contains amount
75; - Effect ledger contains the controlled approved action with amount
75.
Then open History and select the delivered row. The inspector shows:
- what the gateway originally sent;
- what AIT delivered;
- the changed path;
- the receiving-agent response;
- whether an external effect was observable.
6. Try the other decisions¶
Reset before each comparison:
| Decision | Expected result |
|---|---|
| Original | Specialist consumes 25 |
| Drop | Specialist receives nothing; no ledger action |
| Duplicate | Receiver sees correlated copies; its replay behavior becomes visible |
| Forward modified | Specialist consumes the edited value |
Stop every lab-owned process when finished:
Next exercises¶
| Exercise | Command | What it teaches |
|---|---|---|
| MCP tool result | ait lab start --exercise mcp-tool-result |
Change a tool response before the client decides |
| Async artifact | ait lab start --exercise asynchronous-artifact |
Drop, duplicate, replay, and order stream events |
| Real target handoff | Use Lab → Use this setup with my target | Keep the placement and breaks, replace only the upstream |
Continue with the Interception screen guide, the hands-on lab, or the demo and scenario catalog.
Authorized testing only
The packaged lab is intentionally local. Use the real-target workflow only on systems you own or are explicitly authorized to assess.