Agent Chaos
Chaos engineering for autonomous AI agents.
AI agents increasingly depend on unreliable model APIs, tools, databases, and HTTP services. Agent Chaos intentionally disrupts those dependencies so developers can measure whether an agent-like workload tolerates a fault, retries successfully, or fails.
Agent Chaos v0.3 is an early open-source vertical slice. It is framework-independent and does not require an OpenAI or Anthropic API key.
flowchart LR
A["Agent workload"] --> C["Agent Chaos proxy"]
C --> D["HTTP dependency"]
C -. "inject fault" .-> C
Install
The published Python distribution is named agent-chaos-runner; the product and installed
command remain Agent Chaos and agentchaos.
uv tool install agent-chaos-runner
agentchaos --version
Agent Chaos supports Python 3.12+ on macOS and Linux.
Quick start
Clone the repository to run the deterministic local demo without API keys:
git clone https://github.com/Coroz2/agent-chaos.git
cd agent-chaos
uv sync --extra dev --locked
uv run agentchaos run examples/scenarios/api_503_recovery.yaml
The scenario starts its deterministic fake dependency automatically. A successful run ends with
RECOVERED and writes its artifacts under .agentchaos/runs/<run-id>/.
Other examples:
uv run agentchaos run examples/scenarios/no_fault.yaml
uv run agentchaos run examples/scenarios/api_latency_recovery.yaml
uv run agentchaos run examples/scenarios/api_429_recovery.yaml
uv run agentchaos run examples/scenarios/api_429_failure.yaml
uv run agentchaos run examples/scenarios/api_503_failure.yaml
uv run agentchaos run examples/scenarios/http_disconnect_recovery.yaml
uv run agentchaos run examples/scenarios/http_disconnect_failure.yaml
uv run agentchaos run examples/scenarios/http_malformed_json_recovery.yaml
uv run agentchaos run examples/scenarios/http_malformed_json_failure.yaml
The 429, 503, disconnect, and malformed-JSON failure examples deliberately exit with status 1 because recovery is not observed.
Scenario
schema_version: 1
name: api-503-recovery
dependency:
type: http
base_url: http://127.0.0.1:19103
start:
command: [python, fake_api.py, --port, "19103"]
cwd: ..
readiness:
path: /health
workload:
name: demo-agent
command: [python, demo_agent.py]
cwd: ..
proxy_url_env: CUSTOMER_API_URL
fault:
type: http_error
target:
method: GET
path: /customer/*
trigger:
occurrence: 2
status_code: 503
success:
exit_code: 0
The optional managed dependency is intended for local tests. Omit dependency.start when the
upstream already exists. Agent Chaos always exposes the generated proxy URL as
AGENTCHAOS_PROXY_URL; proxy_url_env maps it into the variable an existing workload expects.
Agent Chaos also supports deterministic HTTP rate-limit injection:
fault:
type: http_rate_limit
target:
method: GET
path: /customer/*
trigger:
occurrence: 2
retry_after_seconds: 1
The selected request receives HTTP 429 with an integer Retry-After value and
X-Agent-Chaos-Fault: http_rate_limit; the upstream is not contacted for that request.
To test application-level JSON handling despite a successful HTTP transport status, configure the fixed malformed-JSON fault:
fault:
type: http_malformed_json
target:
method: GET
path: /customer/*
trigger:
occurrence: 2
On the selected occurrence, Agent Chaos returns status 200 with Content-Type: application/json,
X-Agent-Chaos-Fault: http_malformed_json, and one fixed invalid JSON body. It does not contact
the upstream or accept configurable response content. A matching retry that receives valid JSON
is classified as recovery; exiting without a successful matching retry is a failed experiment.
To test recovery from an abruptly terminated HTTP connection, configure the disconnect fault:
fault:
type: http_disconnect
target:
method: GET
path: /customer/*
trigger:
occurrence: 2
Agent Chaos does not forward the selected request upstream and terminates the client connection before a complete response arrives. The portable guarantee is a client-visible transport or HTTP protocol failure; a literal TCP reset and a particular client-library exception are not guaranteed. A matching retry that succeeds through the upstream is classified as recovery.
Results
PASSED: a baseline succeeds, or the workload tolerates injected latency without failure.RECOVERED: a faulted operation fails, a matching retry succeeds, and the workload succeeds.FAILED: execution fails, the fault never fires, or no successful recovery is observed.
An injected disconnect always records a failed operation. It produces RECOVERED only when a
matching retry succeeds; an expected workload exit without that retry produces FAILED.
Successful and recovered experiments exit 0. Experiment failures exit 1, invalid scenarios and
invalid saved reports exit 2, setup or unexpected internal failures exit 3, and interruptions exit
130. Inspecting a structurally valid saved report exits 0 even when its recorded experiment result
is FAILED.
Every valid run contains:
.agentchaos/runs/<run-id>/
├── scenario.yaml
├── events.jsonl
├── stdout.log
├── stderr.log
├── dependency.stdout.log
├── dependency.stderr.log
└── report.json
events.jsonl is a versioned, sequence-ordered event stream. report.json provides stable result
and reason codes plus workload, fault, recovery, timing, and artifact details.
Commands
uv run agentchaos --help
uv run agentchaos --version
uv run agentchaos version
uv run agentchaos validate examples/scenarios/api_503_recovery.yaml
uv run agentchaos run examples/scenarios/api_503_recovery.yaml
uv run agentchaos inspect .agentchaos/runs/<run-id>
uv run agentchaos inspect .agentchaos/runs/<run-id>/report.json
Use --output-dir PATH to place run directories somewhere other than .agentchaos/runs.
inspect accepts either a run directory or its report.json file and prints the same result
summary as run. It strictly validates the saved report without running a workload, starting a
dependency, contacting the network, reading other artifacts, or modifying the run directory.
Documentation
- Project vision: stable mission, principles, capability map, and boundaries.
- Documentation index: authority map for specifications, release guidance, and archived planning.
- v0.3 specification: complete contract for the current released behavior.
- v0.2 specification: immutable contract for the prior release.
- v0.1 specification: immutable contract for the initial release.
Development
uv sync --extra dev
uv run pytest
uv run ruff check .
uv run ruff format --check .
uv run mypy
See CONTRIBUTING.md for the branch, pull request, verification, and release workflow.
Limitations
Agent Chaos supports one HTTP dependency and zero or one fault on macOS and Linux. It is a reverse proxy, not transparent network interception: the workload must accept the proxy base URL through its configuration. Request bodies and responses are buffered up to 10 MiB. Disconnect injection does not provide packet-level reset controls or partial-response faults. Streaming, SSE, WebSockets, CONNECT tunneling, TLS interception, multiple faults, probabilistic triggers, and model-specific grading are not implemented.
Retry classification uses a deterministic fingerprint of method, path, hashed query, and body. It is useful black-box evidence, not proof of the workload's internal intent.
Roadmap
The next logical steps include richer trigger policies and multi-fault campaigns, then another dependency adapter such as MCP. These are broad, nonbinding directions; detailed release scope begins only in an approved version specification.
Licensed under Apache-2.0.
Metadata
Release files for agent-chaos-runner 0.3.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| agent_chaos_runner-0.3.0.tar.gz | 124.5 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| agent_chaos_runner-0.3.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 162.3 kB
Release files / agent_chaos_runner-0.3.0.tar.gz
| Download URL | agent_chaos_runner-0.3.0.tar.gz |
|---|---|
| Size | 124.5 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
064cd6fdb0671456f6ad863049d7b31bdaff6a3946eebdb139b6870460025bd3
|
|
BLAKE2b-256 checksum How to use checksums |
92ef327e452df579c1e5a2223822cdc7c6afc8227a68016b0f2e25a6dede8e3b
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 15, 2026.
Transparency logRelease files / agent_chaos_runner-0.3.0-py3-none-any.whl
| Download URL | agent_chaos_runner-0.3.0-py3-none-any.whl |
|---|---|
| Size | 37.8 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
bd8ed61518e97be304cec4d298da17cd342b9ef65bf2d85508bb7520f2d8d1ce
|
|
BLAKE2b-256 checksum How to use checksums |
b6378502e5e8544743fd46953fd5ca38133ae609c1e2df71120b1150224f9b6c
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 15, 2026.
Transparency log