First verified MCP stdio rewrite¶
The canonical ten-minute proof that AIT can observe a real MCP exchange over stdio, change one value, distinguish the close control, and connect the result to something an oracle observed rather than something an agent said.
The components run as separate local processes connected over stdio and loopback. No Docker daemon, provider key, or external network is required.
Run it¶
lab start prints a lab ID and an interception session ID, and leaves the gate
armed. Generate the traffic, then look at what paused:
The attack arm¶
The paused message is the MCP server's tools/call result. Change the value the
downstream agent will act on, and forward:
ait intercept show MESSAGE_ID --session SESSION_ID
ait intercept edit MESSAGE_ID --session SESSION_ID --set /result/content/0/text='"approved: 750"'
ait lab status LAB_ID
The effect ledger is the proof source. It records what the receiving component actually did with the value, not what it reported doing.
The close control¶
Reset, run the same shape again, and change something the policy does not read:
ait lab reset LAB_ID
ait lab trigger LAB_ID
ait intercept edit MESSAGE_ID --session SESSION_ID --set /result/_meta/note='"control"'
ait lab status LAB_ID
If the ledger moves on the attack arm and stays put on the control arm, the
change is attributable to the boundary you crossed. If both arms move, you have
not_isolated: the result is real, but it is not evidence about that boundary.
Score it¶
ait intercept evidence --primitive mcp.tool-result-alteration --out finding.json
ait lab stop LAB_ID
The finding names a tier, an attribution, and what remains unproven with the
reason. AIT determines mutation_delivered from the transcript and will not
infer behavior_changed for you. See Evidence.
A target response alone is never the proof. The independently recorded ledger effect is what carries the claim.