Skip to content

Targets

Mohammed Danish Amber edited this page Oct 5, 2026 · 1 revision

Targets

Set with --target.

fixture (default)

The bundled deliberately-vulnerable HTTP agent on 127.0.0.1:8000 (and MCP server on 127.0.0.1:8001). Start it with Docker — see The Fixture and Quickstart.

Your own HTTP agent

aphasia run --target http://your-host/chat --model gpt-4o-mini

The HTTP contract the connector expects:

  • Request (POST <target>): JSON {"message": "<payload>", "channel": "<channel>"}.
  • Response: JSON {"reply": "<text>", "tool_calls": [{"name": "...", "args": {...}, "mutating": true|false}, ...]}.
  • Optional plant endpoint: the fixture target also exposes POST /seed to plant canaries. For a generic HTTP target without seeding, canaries can only be proven if your agent echoes them; otherwise findings fall back to mirror_only captures.

Response bodies are capped at 20,000 chars.

MCP server

aphasia run --target <mcp-endpoint>

Drives any MCP server (including a Damn-Vulnerable-MCP server) via the official mcp client. By default it calls a chat tool to deliver and a seed_canaries tool to plant; a target without a seeding tool is handled gracefully (no-op plant), and verification falls back to mirror-capture.

See How It Works for how delivery, canaries and the mirror combine into a verdict.

Clone this wiki locally