meshmapper: topology before exploitation¶
meshmapper converts retained observations into a deterministic communication and trust graph. Its output is a ranked hypothesis about where to test, not a finding that a path works.
The graph preserves what each source observed. It does not upgrade an inferred edge into a delivered exploit or an external effect.
Inputs¶
meshmapper can ingest:
- verified Seam transcripts;
- explicit endpoint inventories;
- A2A Agent Cards;
- MCP tool-list responses;
- reviewed static configuration;
- compatible discovery artifacts.
Each node and edge retains its source reference. Conflicting observations remain visible rather than being silently reconciled.
Deterministic graph¶
The same ordered inputs produce the same node IDs, edge IDs, graph reference, and serialized graph. Determinism makes review and comparison possible; it does not make an inferred relationship true.
Current hypothesis classes include:
| Class | Question to test |
|---|---|
privilege_laundering |
can a low-trust entry reach a higher-privilege sink through an intermediary? |
injection_propagation |
can untrusted content reach an action path without an observed sanitizer boundary? |
confused_deputy |
can a component use its own authority on behalf of a lower-trust caller? |
trust_spoof |
can mutable or unauthenticated discovery data redirect a privileged capability? |
Handoff to a real test¶
Every emitted path remains proven: false. To test one, the researcher must
identify the real protocol hop, place AIT explicitly, define a bounded change,
select a close control, and name the receiver or out-of-band evidence source.
Assay can then bind observations to that path without treating the graph as the
result.
cd agentic-redteam/meshmapper
meshmapper \
--transcript ../seam/transcript.json \
--agent-card billing-card.json \
--mcp-tools-list tools.json \
--graph graph.json \
--out paths.json \
--schema ../schema