End-to-end assessment¶
The reference deployment shape for an engagement: stand up a private workspace, place AIT in the path, run each attack against its close control, score what the evidence actually supports, and tear down.
Set up¶
Placement is explicit. AIT is not a transparent interception appliance: the sender has to use the listener AIT prints, so you decide where the boundary sits and the target's operators can see it:
ait connections add --protocol a2a_jsonrpc --upstream http://127.0.0.1:9000
ait connections test CONNECTION_ID
ait intercept start --connection CONNECTION_ID --direction request
Break narrowly. A session with no break conditions pauses every decoded message and holds each sender's connection open until you decide, which will change the target's behavior before you have attacked anything:
ait intercept start --connection CONNECTION_ID --where 'json.params.message.parts.0.text:contains:refund'
Give redirects somewhere real to land¶
An endpoint substitution that points at a dead port proves routing changed. It cannot show what an attacker does with the redirected traffic, which is the finding a client cares about. Stand up receivers you control:
ait intercept shadow start a2a-agent --name shadow-specialist
ait intercept shadow observations --name shadow-specialist
Shadows bind to loopback only. They record what arrived, including credential
headers in full: a substituted destination receiving a bearer token is the
credential-relay finding, so the capture is deliberate. Observation files are
written 0600.
Run each attack against its control¶
ait intercept attack --target MESSAGE_ID
ait intercept evidence --primitive a2a.agent-card-endpoint-substitution --out finding.json
Two arms, minimally different. The attack arm crosses the boundary; the close
control changes something equally visible that the receiver does not act on. A
result that moves both arms is not_isolated and should be reported that way.
Field sequence¶
- Capture authorization, in-scope locators, prohibited effects, retention, and contacts before touching anything.
- Place AIT explicitly at the stdio, HTTP, SSE or WebSocket boundary.
- Record a baseline with interception on and no rules armed: if the inert path already behaves differently, stop and diagnose framing, TLS, streaming or timeout behavior before running attacks.
- Choose what would count as an independent observation, and verify you can reset between arms.
- Run attack and close control from the same reset state.
- Promote only what the claimed tier supports. A receiver that says it did something has not shown you that it did.
- Retest after remediation against the same baseline.
- Export with
--redactedbefore handing a record to anyone;--rawis complete capture and is labeled as such. - Remove listeners, shadow endpoints, temporary state and credentials.
ait intercept export SESSION_ID --format jsonl --redacted --out session.jsonl
ait intercept stop SESSION_ID --pending forward
stop will ask what to do with anything still paused. Paused messages do not
expire and AIT will not decide silently: a message dropped at teardown is a
message the target never received, and that belongs in the record.