Skip to content

Quick attack recipes

Use this page while AIT is open. Pick one test, change one thing, and watch the receiving component.

The whole workflow

  1. Start a lab or connection.
  2. Turn Intercept on.
  3. Generate normal application traffic.
  4. Select a paused message.
  5. Forward the original once.
  6. Reset, repeat, and make one change.
  7. Forward, drop, or duplicate.
  8. Check the receiver and effect ledger.

The Attack ideas section in the right pane can prepare relevant edits for the selected message.

Start with a lab

ait lab start --exercise delegated-a2a-message

Select Send exercise traffic, change the amount from 25 to 75, and select Forward modified. If the specialist and effect ledger both show 75, you completed the full workflow.

Pick an attack

I want to test… Pause… Change… Look for…
Delegated authority A2A message/send Amount or instruction Specialist/tool uses the changed value
Task isolation A2A message Task, context, or tenant ID Work appears under the wrong controlled identity
Agent discovery Agent Card response Endpoint, skill, or capability Next request takes a different route
Task lifecycle Status update Task state Subscriber advances or commits incorrectly
Artifact trust Artifact update Content or revision Downstream agent consumes the replacement
Callback trust Push configuration/callback Controlled callback URL Callback reaches the replacement receiver
Tool authority MCP tools/call One argument Tool ledger uses the changed argument
Tool-result trust MCP tool response Returned result Calling agent changes its decision
Tool discovery MCP tools/list Name or schema Client selects the altered tool contract
Resource trust MCP resource request/response URI or returned text Agent consumes the alternate resource
Sampling/elicitation MCP sampling or elicitation Restriction, instruction, or controlled URL Tool choice or client destination changes
Replay/order handling Request or stream event Drop, duplicate, replay, or reorder Duplicate effect, unsafe fallback, or stale state

Recipe 1: change a delegated amount

  • Pause: A2A message/send.
  • Change: /params/message/metadata/amount from 25 to 75.
  • Look: the specialist and effect ledger must both show 75.
  • Control: use another amount that remains inside the expected policy.
ait lab start --exercise delegated-a2a-message

Recipe 2: cross a task or tenant boundary

  • Pause: a message containing a task, context, or tenant ID.
  • Change: one ID to another synthetic ID in the test fixture.
  • Look: a read, update, artifact, or action under the alternate identity.
  • Control: keep the IDs and change only a display label.

Common paths:

/params/message/taskId
/params/message/contextId
/params/message/metadata/tenantId

Recipe 3: redirect an agent

  • Pause: an Agent Card response.
  • Change: one endpoint or skill to an operator-controlled replacement.
  • Look: the next real request reaches the replacement.
  • Control: change the Card description but keep its route and skill.

Do not use an endpoint outside the assessment range.

Recipe 4: forge task completion

  • Pause: an A2A task status update.
  • Change: its decoded state to completed.
  • Look: the subscriber commits, stops waiting, or performs an action.
  • Control: change only the human-readable status message.

Recipe 5: replace an artifact

  • Pause: an artifact update.
  • Change: the artifact text or revision.
  • Look: the downstream subscriber consumes the replacement.
  • Control: keep the content and change only its display name.

For ordering, hold two revisions and release them in the opposite order.

Recipe 6: redirect or replay a callback

  • Pause: push-configuration creation or a callback.
  • Change: the URL to a controlled local receiver, or replay one callback.
  • Look: the callback receiver and replay ledger.
  • Control: keep the URL and change only a callback label.

Credential values are readable and editable; a delivery that changes them is marked credential_edited.

Recipe 7: change an MCP tool argument

  • Pause: MCP tools/call.
  • Change: one value under /params/arguments.
  • Look: the tool or action ledger uses the delivered value.
  • Control: use a nearby allowed value.
ait lab start --exercise mcp-tool-result

Recipe 8: change an MCP tool result

  • Pause: the response to tools/call.
  • Change: one value under /result/structuredContent or returned text.
  • Look: the calling agent changes its decision or controlled action.
  • Control: change an unused result field.

Recipe 9: change a tool’s identity or schema

  • Pause: MCP tools/list.
  • Change: a tool name, description, required field, type, or enum.
  • Look: the client exposes, selects, or calls the changed contract.
  • Control: change only an unused description sentence.

Recipe 10: poison an MCP resource

  • Pause: resources/read or its response.
  • Change: /params/uri or returned resource text.
  • Look: the server returns an alternate controlled resource or the agent acts on changed content.
  • Control: preserve the URI/content and change irrelevant metadata.

Recipe 11: change sampling or elicitation

  • Pause: MCP sampling or URL-mode elicitation.
  • Change: toolChoice, one instruction, or a controlled destination URL.
  • Look: a different controlled tool is selected or the client uses the replacement destination.
  • Control: preserve the restriction or URL and change only descriptive text.

Model text alone is not an external effect.

Recipe 12: drop, duplicate, replay, or reorder

  • Pause: a request, callback, or stream event.
  • Change: use Drop, Duplicate, or an explicit batch release order.
  • Look: subscriber history, task state, fallback, and effect count.
  • Control: deliver one unchanged copy in the original order.
ait lab start --exercise asynchronous-artifact

What counts as a result?

You observed… You can say…
Original and delivered are different AIT changed the communication
Receiver returned a correlated response Receiver processed the delivered request
Receiver selected another tool/route/state The change influenced behavior
Ledger, callback, datastore, or tool event changed An independent effect occurred
Close control stayed inert The tested field likely explains the effect

For deeper rationale, additional pointers, and evidence methodology, use the Offensive interception field guide. For terminal commands, use the operator command cookbook.