-
Notifications
You must be signed in to change notification settings - Fork 0
Contributing
Mohammed Danish Amber edited this page Oct 5, 2026
·
1 revision
New seed payloads and scenarios are the easiest and most valuable contributions.
Full guide: CONTRIBUTING.md in the repo.
- Python 3.11+,
uv. The package lives inengine/. - Engine tests (offline):
cd engine && uv run pytest -m "not live" - Fixture tests (sandbox-inert + end-to-end seed run):
uv run --with-editable ./engine --with flask --with "mcp>=2" --with pytest python -m pytest fixture/tests
Edit engine/src/aphasia/data/payloads.yaml under the matching scenario id (order matters
for multi-phase scenarios). See Seed Payload Library. Only redistributable (Apache-2.0)
payloads. Verify with aphasia run --mode seed against the fixture.
- Add an entry to
engine/src/aphasia/data/scenarios.yaml(id,category,channel,goal,success_condition,atlas,owasp). - Give the The Fixture a deliberately-vulnerable, sandbox-inert surface in
fixture/agent/app.py(string/dict ops only) and a test infixture/tests/test_agent_sandbox.py. - Add seed payloads in
payloads.yaml. - If it maps to a MITRE ATLAS technique, add the id + display name in
engine/src/aphasia/report/render.py.
- Every change ships with a test. Keep PRs small and focused.
- Never weaken a safety invariant — see Security and Safety.
- By contributing you agree your work is licensed under Apache-2.0.