-
Notifications
You must be signed in to change notification settings - Fork 1
Home
Mohammed Danish Amber edited this page Oct 5, 2026
·
2 revisions
Agentic BAS — breach & attack simulation for AI agents and MCP servers.
Aphasia Agentry drives an attacker (curated seed payloads and/or any LLM) against an AI agent or MCP server, proves which attacks reach real impact using per-run canaries — not an LLM judge — and reports the results mapped to the OWASP LLM Top 10 and MITRE ATLAS.
- Source & README: https://github.com/mddanish/Aphasia-Agentry
- PyPI: https://pypi.org/project/aphasia-agentry/
- Installation — pip / uvx / from source
- Quickstart — first canary-proven run in ~2 minutes (no API key)
- CLI Reference — every command and flag
- How It Works — the attack loop, canaries, mirror, verdicts
-
Attacker Modes —
seed(no LLM),adaptive(LLM),hybrid(both) - Scenarios — the 11 OWASP LLM Top 10 scenarios and their ATLAS mapping
- LLM Providers — any model via litellm (OpenAI, Anthropic, Ollama, local, …)
- Targets — the bundled fixture, your own HTTP agent, or any MCP server
- The Report — HTML/JSON report fields and verdicts
-
Evidence Schema — the append-only
evidence.jsonl -
Seed Payload Library — the curated
payloads.yaml - The Fixture — the deliberately-vulnerable, sandbox-inert target
- Security and Safety — the non-negotiable invariants
- Contributing — add payloads, scenarios, fixture surfaces
- Development and Release — tests, CI, build, PyPI
- Troubleshooting
- Roadmap
The bundled fixture is intentionally vulnerable. Run it on localhost only; never expose it.