Repository navigation
The Fixture
A deliberately-vulnerable target the engine drives, so you can try Aphasia Agentry without your own agent. Real exploit, fake blast radius.
INTENTIONALLY VULNERABLE. Run on localhost only; never expose it. Enforced by the Docker compose publishing on
127.0.0.1only.
Location: fixture/ — an HTTP agent (fixture/agent/) and an MCP server (fixture/mcp/).
docker compose -f fixture/docker-compose.yml up -d # agent 127.0.0.1:8000, mcp 127.0.0.1:8001
docker compose -f fixture/docker-compose.yml down
A scripted (non-LLM) "support agent" with vulnerable, keyword-triggered surfaces — one per
OWASP category (direct/indirect injection, tool misuse, data exfil, MCP poisoning, memory
poisoning, output handling, system-prompt leak, RAG exfil, misinformation, denial-of-wallet).
Tools (lookup_order, issue_refund, send_email, …) are reported, never executed.
The fixture performs no real filesystem, exec, env, or network action from any request:
- it imports only
re+ Flask (agent) /re+ themcpSDK (server) — nothing dangerous is reachable from a request; - planted data is fabricated per run from the engine's canaries;
- a request asking to read
/etc/passwdor run a shell returns a fabricated refusal; - tests (
fixture/tests/) assert this with boom-spies onopen/subprocess/os.system/socketplus a source scan.
This is the same discipline the engine's record-only mirror enforces — see Security and Safety.