Skip to content

The Fixture

Mohammed Danish Amber edited this page Oct 5, 2026 · 1 revision

The Fixture

A deliberately-vulnerable target the engine drives, so you can try Aphasia Agentry without your own agent. Real exploit, fake blast radius.

INTENTIONALLY VULNERABLE. Run on localhost only; never expose it. Enforced by the Docker compose publishing on 127.0.0.1 only.

Location: fixture/ — an HTTP agent (fixture/agent/) and an MCP server (fixture/mcp/).

Run it

docker compose -f fixture/docker-compose.yml up -d     # agent 127.0.0.1:8000, mcp 127.0.0.1:8001
docker compose -f fixture/docker-compose.yml down

What it exposes

A scripted (non-LLM) "support agent" with vulnerable, keyword-triggered surfaces — one per OWASP category (direct/indirect injection, tool misuse, data exfil, MCP poisoning, memory poisoning, output handling, system-prompt leak, RAG exfil, misinformation, denial-of-wallet). Tools (lookup_order, issue_refund, send_email, …) are reported, never executed.

Sandbox-inert guarantee

The fixture performs no real filesystem, exec, env, or network action from any request:

  • it imports only re + Flask (agent) / re + the mcp SDK (server) — nothing dangerous is reachable from a request;
  • planted data is fabricated per run from the engine's canaries;
  • a request asking to read /etc/passwd or run a shell returns a fabricated refusal;
  • tests (fixture/tests/) assert this with boom-spies on open/subprocess/os.system/ socket plus a source scan.

This is the same discipline the engine's record-only mirror enforces — see Security and Safety.

Clone this wiki locally