Agent Chaos
Chaos engineering for autonomous AI agents.
AI agents increasingly depend on unreliable model APIs, tools, databases, and HTTP services. Agent Chaos intentionally disrupts those dependencies so developers can measure whether an agent-like workload tolerates a fault, retries successfully, or fails.
Agent Chaos v0.1 is an early open-source vertical slice. It is framework-independent and does not require an OpenAI or Anthropic API key.
flowchart LR
A["Agent workload"] --> C["Agent Chaos proxy"]
C --> D["HTTP dependency"]
C -. "inject fault" .-> C
Install
The published Python distribution is named agent-chaos-runner; the product and installed
command remain Agent Chaos and agentchaos.
uv tool install agent-chaos-runner
agentchaos --version
Agent Chaos supports Python 3.12+ on macOS and Linux.
Quick start
Clone the repository to run the deterministic local demo without API keys:
git clone https://github.com/Coroz2/agent-chaos.git
cd agent-chaos
uv sync --extra dev
uv run agentchaos run examples/scenarios/api_503_recovery.yaml
The scenario starts its deterministic fake dependency automatically. A successful run ends with
RECOVERED and writes its artifacts under .agentchaos/runs/<run-id>/.
Other examples:
uv run agentchaos run examples/scenarios/no_fault.yaml
uv run agentchaos run examples/scenarios/api_latency_recovery.yaml
uv run agentchaos run examples/scenarios/api_503_failure.yaml
The final command deliberately exits with status 1 because recovery is not observed.
Scenario
schema_version: 1
name: api-503-recovery
dependency:
type: http
base_url: http://127.0.0.1:19103
start:
command: [python, fake_api.py, --port, "19103"]
cwd: ..
readiness:
path: /health
workload:
name: demo-agent
command: [python, demo_agent.py]
cwd: ..
proxy_url_env: CUSTOMER_API_URL
fault:
type: http_error
target:
method: GET
path: /customer/*
trigger:
occurrence: 2
status_code: 503
success:
exit_code: 0
The optional managed dependency is intended for local tests. Omit dependency.start when the
upstream already exists. Agent Chaos always exposes the generated proxy URL as
AGENTCHAOS_PROXY_URL; proxy_url_env maps it into the variable an existing workload expects.
Results
PASSED: a baseline succeeds, or the workload tolerates injected latency without failure.RECOVERED: a faulted operation fails, a matching retry succeeds, and the workload succeeds.FAILED: execution fails, the fault never fires, or no successful recovery is observed.
Successful and recovered experiments exit 0. Experiment failures exit 1, invalid scenarios exit 2, setup failures exit 3, and interruptions exit 130.
Every valid run contains:
.agentchaos/runs/<run-id>/
├── scenario.yaml
├── events.jsonl
├── stdout.log
├── stderr.log
├── dependency.stdout.log
├── dependency.stderr.log
└── report.json
events.jsonl is a versioned, sequence-ordered event stream. report.json provides stable result
and reason codes plus workload, fault, recovery, timing, and artifact details.
Commands
uv run agentchaos --help
uv run agentchaos --version
uv run agentchaos version
uv run agentchaos validate examples/scenarios/api_503_recovery.yaml
uv run agentchaos run examples/scenarios/api_503_recovery.yaml
Use --output-dir PATH to place run directories somewhere other than .agentchaos/runs.
Development
uv sync --extra dev
uv run pytest
uv run ruff check .
uv run ruff format --check .
uv run mypy
Limitations
v0.1 supports one HTTP dependency and zero or one fault on macOS and Linux. It is a reverse proxy, not transparent network interception: the workload must accept the proxy base URL through its configuration. Request bodies and responses are buffered up to 10 MiB. Streaming, SSE, WebSockets, CONNECT tunneling, TLS interception, multiple faults, probabilistic triggers, and model-specific grading are not implemented.
Retry classification uses a deterministic fingerprint of method, path, hashed query, and body. It is useful black-box evidence, not proof of the workload's internal intent.
Roadmap
The next logical steps are richer HTTP failures such as 429s and connection resets, richer trigger policies and multi-fault campaigns, then another dependency adapter such as MCP.
Licensed under Apache-2.0.
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file agent_chaos_runner-0.1.0.tar.gz.
File metadata
- Download URL: agent_chaos_runner-0.1.0.tar.gz
- Upload date:
- Size: 95.3 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
8ddff6c62174a0b597fa0a58c83702df2df67f4e4eef41881018818bd932a920
|
|
| MD5 |
5f05fbc20e259ac1324b4f79112728bd
|
|
| BLAKE2b-256 |
b6167df6476ca1bf79372f5c93676ac42ab63a66760cf88255ffeff37f299d04
|
Provenance
The following attestation bundles were made for agent_chaos_runner-0.1.0.tar.gz:
Publisher:
release.yml on Coroz2/agent-chaos
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
agent_chaos_runner-0.1.0.tar.gz -
Subject digest:
8ddff6c62174a0b597fa0a58c83702df2df67f4e4eef41881018818bd932a920 - Sigstore transparency entry: 2456731469
- Sigstore integration time:
-
Permalink:
Coroz2/agent-chaos@f5d3523567d0c2b7478167f4626c7bac5232a38e -
Branch / Tag:
refs/tags/v0.1.0 - Owner: https://github.com/Coroz2
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@f5d3523567d0c2b7478167f4626c7bac5232a38e -
Trigger Event:
push
-
Statement type:
File details
Details for the file agent_chaos_runner-0.1.0-py3-none-any.whl.
File metadata
- Download URL: agent_chaos_runner-0.1.0-py3-none-any.whl
- Upload date:
- Size: 28.2 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
cb71a15c8990189b287be7a1cb20a9518e234b02221151379bee7290342c9101
|
|
| MD5 |
abdfa6f7270a04030e2da9108f028322
|
|
| BLAKE2b-256 |
9a07cac3393a28d7f4620f06efa37e8b504de53b0b1ca10c65d274821d0250e1
|
Provenance
The following attestation bundles were made for agent_chaos_runner-0.1.0-py3-none-any.whl:
Publisher:
release.yml on Coroz2/agent-chaos
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
agent_chaos_runner-0.1.0-py3-none-any.whl -
Subject digest:
cb71a15c8990189b287be7a1cb20a9518e234b02221151379bee7290342c9101 - Sigstore transparency entry: 2456731827
- Sigstore integration time:
-
Permalink:
Coroz2/agent-chaos@f5d3523567d0c2b7478167f4626c7bac5232a38e -
Branch / Tag:
refs/tags/v0.1.0 - Owner: https://github.com/Coroz2
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@f5d3523567d0c2b7478167f4626c7bac5232a38e -
Trigger Event:
push
-
Statement type: