Skip to content

Shared Schemas

The contracts an interception session actually produces and reads.

Interception

  • ait.intercept-session/v1: one session bound to one connection.
  • ait.intercept-message/v2: separates the immutable decoded body from an editable transport envelope, carries the sender's pre-rule message as wire_original when a transform rule fired, and flags credential_edited when delivered credential headers differ from what the sender sent.
  • ait.intercept-decision/v2: body, envelope, raw fallback, forwarding action, and bounded replay count, without replacing the original message.
  • ait.intercept-batch-decision/v1: requested and actual release order for selected stream events. Both are recorded because a stream released out of the requested order is itself a finding.
  • ait.intercept-profile/v1: break conditions and session policy.
  • ait.live-rule-set/v1: the JSON-Pointer patch rules scoped to one session.
  • ait.edit-suggestion/v1: an attack primitive rendered against one message.
  • ait.intercept-session-export/v1: the redacted or raw session record.

The v1 message and decision readers remain supported.

Evidence

  • ait.intercept-evidence/v1: the finding: tier, attribution, chain steps, observations, and what remains unproven with the reason it is unproven.
  • ait.intercept-arms/v1: attack and close-control arms recorded together, so attribution is derived rather than asserted.
  • ait.shadow-observation/v1: what a shadow endpoint received: method, path, headers in full, and body. Written 0600; bounded at 2,000 observations.
  • ait.evidence-bundle/v1, ait.evidence-signature/v1: portable manifest linking artifacts, provenance, hashes, redaction and signature state.
  • ait.artifact-envelope/v1: the versioned envelope every platform artifact shares.

A tier cannot be skipped, and an operator assertion cannot substitute for an observation. See Evidence.

Transcripts

agentic-redteam/schema/transcript.schema.json is the authoritative transcript contract; Seam carries an identical copy at agentic-redteam/seam/schemas/. Chain 1.0, 2.0 and 2.1 all verify. Each record carries prev_hash, so records are independently verifiable and the JSONL sidecar can be appended to during a session without re-validating the whole file per record.

agentic-redteam/seam/seam transcript verify \
  --schema agentic-redteam/schema/transcript.schema.json \
  --transcript out.json

Labs

  • ait.intercept-lab/v3: operator recipe, lifecycle progress, receiver proof source, and verified cleanup receipt for process-backed local exercises. The v1/v2 readers remain supported.

Target handoff uses the existing connection contract and performs no contact during preparation.

Targets, connections and runtime

  • ait.connection/v1: listener, upstream, transport and TLS references.
  • ait.offensive-runtime/v2 … /v8: saved runtime documents, with the older versions retained as compatibility readers.
  • ait.attack-runtime-jsonl/v1: the JSONL boundary an active-state target speaks.
  • ait.state-snapshot/v1: captured scoped state, for comparing a receiver's state before and after.
  • ait.attack-primitive/v1: the catalogued primitives: selector, injection, observation, close control, and stated limitation.

A stored runtime document may not contain an inline secret. Credential fields carry env:NAME references resolved at the point of use, and a document holding a literal value is refused rather than redacted: redacting would still have accepted the value once.

Workspace and console

ait.workspace/v1, ait.operator-snapshot/v1, ait.cockpit-status/v2, ait.plugin-jsonl/v1, ait.plugin-manifest, ait.multimodal-input/v1, ait.discovery-failure/v1, ait.adapter/v1 and its capability and contract companions.

Removed

The campaign, campaign-results, experiment, mesh, certification, reproducer, interleaving, checkpoint, and mitigation-profile schema families belonged to the removed campaign engine. Their unreferenced files have been deleted. They are not compatibility contracts and must not be recreated as documentation-only schemas.