Skip to content

Operate one exchange

This guide follows the operator's path through one bounded exchange. For component ownership, transport placement, credential handling, and storage, start with the system architecture. For command details, use the direct interception reference.

A request leaves the sender, is decoded into one complete frame at the Seam boundary, is held for a researcher decision, and is released to the selected receiver. A request leaves the sender, is decoded into one complete frame at the Seam boundary, is held for a researcher decision, and is released to the selected receiver. A mobile view of a complete message moving through emit, decode, hold, decide, release, and receiver-processing states. A mobile view of a complete message moving through emit, decode, hold, decide, release, and receiver-processing states.

The boundary holds one complete protocol message. The researcher aims at a named operation, chooses one arm, releases it, and then reads evidence from the receiver and oracle.

1. Aim

Start from a saved connection whose listener, upstream, transport, and TLS references you have already reviewed. Narrow the pause condition to the direction and operation named by the hypothesis.

ait intercept start \
  --connection CONNECTION_ID \
  --direction request \
  --operation tools/call

Add a payload predicate only when the experiment requires it:

ait intercept start \
  --connection CONNECTION_ID \
  --where 'json.params.message.parts.0.text:contains:refund'

A session with no break condition pauses every decoded message. That can change timing before the intervention begins, so broad capture is an explicit design choice, not a neutral default.

2. Pause and inspect

Drive the sender normally, then identify the complete message that stopped.

ait intercept pending SESSION_ID
ait intercept show MESSAGE_ID --session SESSION_ID

Confirm the protocol, operation, direction, correlation fields, parse state, and original body before changing anything. If the expected message is absent, diagnose the route or selector. Do not substitute a nearby message because it happened to pause.

3. Choose the arm

The attack and close control should differ only in the property named by the hypothesis. A catalogued primitive carries that pair and states its limitation.

ait intercept attack --target MESSAGE_ID
ait intercept attack mcp.tool-result-alteration --target MESSAGE_ID
ait intercept attack mcp.tool-result-alteration \
  --target NEXT_MESSAGE_ID \
  --arm control

Applicability means the selector and both patches address this message. It does not mean the receiver is vulnerable. For a target-specific field, override the value explicitly or author a primitive in the workspace. Preserve the exact attack and control values with the run record.

4. Deliver one decision

Use one explicit terminal action. edit validates, re-encodes, and forwards the modified message. forward delivers the immutable original. drop resolves the pause without upstream delivery.

ait intercept edit MESSAGE_ID \
  --session SESSION_ID \
  --arm attack \
  --set /params/arguments/account='"acct-restricted"'

ait intercept forward NEXT_MESSAGE_ID --session SESSION_ID --arm control

When a transform rule is armed, the Cockpit shows the sender's original and the rule-applied representation separately. Use the decision that matches the protocol. In particular, bypass the rule when the baseline requires the sender's wire bytes. The transcript records which representation crossed the boundary.

5. Inspect before claiming

Read the delivery transcript, receiver observation, and independent oracle as different sources.

Source What it supports What it cannot establish alone
chained before-and-after transcript which representation AIT delivered what the receiver did
receiver state or correlated processing that the receiver processed the exchange that the tested property caused the outcome
attack and close-control observations whether the outcome differed between arms an effect outside the measured target
external oracle with a recorded baseline a target-appropriate downstream state transition generality beyond the tested system
ait intercept evidence --primitive mcp.tool-result-alteration --out finding.json
ait intercept export SESSION_ID --format jsonl --redacted --out session.jsonl
ait intercept stop SESSION_ID --pending forward

The finding must stop at the strongest observation that exists. A changed message is delivery evidence. A receiver statement is not an external oracle. A baseline that was already positive voids that probe.

Continue from here

R/R/R boundary

Operating the interception correctly proves only what the recorded sources show. External validity comes from a named external target, repeated trials, a close control, and an independent effect source, not from the interface or the realism of the payload.