Shared Schemas¶
The contracts an interception session actually produces and reads.
Interception¶
ait.intercept-session/v1: one session bound to one connection.ait.intercept-message/v2: separates the immutable decoded body from an editable transport envelope, carries the sender's pre-rule message aswire_originalwhen a transform rule fired, and flagscredential_editedwhen delivered credential headers differ from what the sender sent.ait.intercept-decision/v2: body, envelope, raw fallback, forwarding action, and bounded replay count, without replacing the original message.ait.intercept-batch-decision/v1: requested and actual release order for selected stream events. Both are recorded because a stream released out of the requested order is itself a finding.ait.intercept-profile/v1: break conditions and session policy.ait.live-rule-set/v1: the JSON-Pointer patch rules scoped to one session.ait.edit-suggestion/v1: an attack primitive rendered against one message.ait.intercept-session-export/v1: the redacted or raw session record.
The v1 message and decision readers remain supported.
Evidence¶
ait.intercept-evidence/v1: the finding: tier, attribution, chain steps, observations, and what remains unproven with the reason it is unproven.ait.intercept-arms/v1: attack and close-control arms recorded together, so attribution is derived rather than asserted.ait.shadow-observation/v1: what a shadow endpoint received: method, path, headers in full, and body. Written0600; bounded at 2,000 observations.ait.evidence-bundle/v1,ait.evidence-signature/v1: portable manifest linking artifacts, provenance, hashes, redaction and signature state.ait.artifact-envelope/v1: the versioned envelope every platform artifact shares.
A tier cannot be skipped, and an operator assertion cannot substitute for an observation. See Evidence.
Transcripts¶
agentic-redteam/schema/transcript.schema.json is the authoritative transcript
contract; Seam carries an identical copy at agentic-redteam/seam/schemas/.
Chain 1.0, 2.0 and 2.1 all verify. Each record carries prev_hash, so records
are independently verifiable and the JSONL sidecar can be appended to during a
session without re-validating the whole file per record.
agentic-redteam/seam/seam transcript verify \
--schema agentic-redteam/schema/transcript.schema.json \
--transcript out.json
Labs¶
ait.intercept-lab/v3: operator recipe, lifecycle progress, receiver proof source, and verified cleanup receipt for process-backed local exercises. The v1/v2 readers remain supported.
Target handoff uses the existing connection contract and performs no contact during preparation.
Targets, connections and runtime¶
ait.connection/v1: listener, upstream, transport and TLS references.ait.offensive-runtime/v2…/v8: saved runtime documents, with the older versions retained as compatibility readers.ait.attack-runtime-jsonl/v1: the JSONL boundary an active-state target speaks.ait.state-snapshot/v1: captured scoped state, for comparing a receiver's state before and after.ait.attack-primitive/v1: the catalogued primitives: selector, injection, observation, close control, and stated limitation.
A stored runtime document may not contain an inline secret. Credential fields
carry env:NAME references resolved at the point of use, and a document holding
a literal value is refused rather than redacted: redacting would still have
accepted the value once.
Workspace and console¶
ait.workspace/v1, ait.operator-snapshot/v1, ait.cockpit-status/v2,
ait.plugin-jsonl/v1, ait.plugin-manifest, ait.multimodal-input/v1,
ait.discovery-failure/v1, ait.adapter/v1 and its capability and contract
companions.
Removed¶
The campaign, campaign-results, experiment, mesh, certification, reproducer, interleaving, checkpoint, and mitigation-profile schema families belonged to the removed campaign engine. Their unreferenced files have been deleted. They are not compatibility contracts and must not be recreated as documentation-only schemas.