Quick attack recipes¶
Use this page while AIT is open. Pick one test, change one thing, and watch the receiving component.
The whole workflow¶
- Start a lab or connection.
- Turn Intercept on.
- Generate normal application traffic.
- Select a paused message.
- Forward the original once.
- Reset, repeat, and make one change.
- Forward, drop, or duplicate.
- Check the receiver and effect ledger.
The Attack ideas section in the right pane can prepare relevant edits for the selected message.
Start with a lab¶
Select Send exercise traffic, change the amount from 25 to 75, and
select Forward modified. If the specialist and effect ledger both show
75, you completed the full workflow.
Pick an attack¶
| I want to test… | Pause… | Change… | Look for… |
|---|---|---|---|
| Delegated authority | A2A message/send |
Amount or instruction | Specialist/tool uses the changed value |
| Task isolation | A2A message | Task, context, or tenant ID | Work appears under the wrong controlled identity |
| Agent discovery | Agent Card response | Endpoint, skill, or capability | Next request takes a different route |
| Task lifecycle | Status update | Task state | Subscriber advances or commits incorrectly |
| Artifact trust | Artifact update | Content or revision | Downstream agent consumes the replacement |
| Callback trust | Push configuration/callback | Controlled callback URL | Callback reaches the replacement receiver |
| Tool authority | MCP tools/call |
One argument | Tool ledger uses the changed argument |
| Tool-result trust | MCP tool response | Returned result | Calling agent changes its decision |
| Tool discovery | MCP tools/list |
Name or schema | Client selects the altered tool contract |
| Resource trust | MCP resource request/response | URI or returned text | Agent consumes the alternate resource |
| Sampling/elicitation | MCP sampling or elicitation | Restriction, instruction, or controlled URL | Tool choice or client destination changes |
| Replay/order handling | Request or stream event | Drop, duplicate, replay, or reorder | Duplicate effect, unsafe fallback, or stale state |
Recipe 1: change a delegated amount¶
- Pause: A2A
message/send. - Change:
/params/message/metadata/amountfrom25to75. - Look: the specialist and effect ledger must both show
75. - Control: use another amount that remains inside the expected policy.
Recipe 2: cross a task or tenant boundary¶
- Pause: a message containing a task, context, or tenant ID.
- Change: one ID to another synthetic ID in the test fixture.
- Look: a read, update, artifact, or action under the alternate identity.
- Control: keep the IDs and change only a display label.
Common paths:
Recipe 3: redirect an agent¶
- Pause: an Agent Card response.
- Change: one endpoint or skill to an operator-controlled replacement.
- Look: the next real request reaches the replacement.
- Control: change the Card description but keep its route and skill.
Do not use an endpoint outside the assessment range.
Recipe 4: forge task completion¶
- Pause: an A2A task status update.
- Change: its decoded state to
completed. - Look: the subscriber commits, stops waiting, or performs an action.
- Control: change only the human-readable status message.
Recipe 5: replace an artifact¶
- Pause: an artifact update.
- Change: the artifact text or revision.
- Look: the downstream subscriber consumes the replacement.
- Control: keep the content and change only its display name.
For ordering, hold two revisions and release them in the opposite order.
Recipe 6: redirect or replay a callback¶
- Pause: push-configuration creation or a callback.
- Change: the URL to a controlled local receiver, or replay one callback.
- Look: the callback receiver and replay ledger.
- Control: keep the URL and change only a callback label.
Credential values are readable and editable; a delivery that changes them is marked credential_edited.
Recipe 7: change an MCP tool argument¶
- Pause: MCP
tools/call. - Change: one value under
/params/arguments. - Look: the tool or action ledger uses the delivered value.
- Control: use a nearby allowed value.
Recipe 8: change an MCP tool result¶
- Pause: the response to
tools/call. - Change: one value under
/result/structuredContentor returned text. - Look: the calling agent changes its decision or controlled action.
- Control: change an unused result field.
Recipe 9: change a tool’s identity or schema¶
- Pause: MCP
tools/list. - Change: a tool name, description, required field, type, or enum.
- Look: the client exposes, selects, or calls the changed contract.
- Control: change only an unused description sentence.
Recipe 10: poison an MCP resource¶
- Pause:
resources/reador its response. - Change:
/params/urior returned resource text. - Look: the server returns an alternate controlled resource or the agent acts on changed content.
- Control: preserve the URI/content and change irrelevant metadata.
Recipe 11: change sampling or elicitation¶
- Pause: MCP sampling or URL-mode elicitation.
- Change:
toolChoice, one instruction, or a controlled destination URL. - Look: a different controlled tool is selected or the client uses the replacement destination.
- Control: preserve the restriction or URL and change only descriptive text.
Model text alone is not an external effect.
Recipe 12: drop, duplicate, replay, or reorder¶
- Pause: a request, callback, or stream event.
- Change: use Drop, Duplicate, or an explicit batch release order.
- Look: subscriber history, task state, fallback, and effect count.
- Control: deliver one unchanged copy in the original order.
What counts as a result?¶
| You observed… | You can say… |
|---|---|
| Original and delivered are different | AIT changed the communication |
| Receiver returned a correlated response | Receiver processed the delivered request |
| Receiver selected another tool/route/state | The change influenced behavior |
| Ledger, callback, datastore, or tool event changed | An independent effect occurred |
| Close control stayed inert | The tested field likely explains the effect |
For deeper rationale, additional pointers, and evidence methodology, use the Offensive interception field guide. For terminal commands, use the operator command cookbook.