Aphasia Agentry
Agentic BAS — breach & attack simulation for AI agents and MCP servers. Drive an attacker (curated seed payloads and/or any LLM) against a target, prove impact with per-run canaries, and get a report mapped to the OWASP LLM Top 10 and MITRE ATLAS.
Install
pip install aphasia-agentry # or: uvx aphasia-agentry, pipx install aphasia-agentry
Why
Most agent red-teaming grades a model's output with an LLM judge. Aphasia Agentry asks a harder question — did the attack actually reach impact? — and answers it with evidence:
- Proof, not judgement. A finding is a touched canary record, a used honey token, or a mutating tool call captured by a record-only mirror. Never a model's self-assessment.
- Any LLM, or none. Seed mode runs curated payloads with no LLM at all (reproducible, runs in seconds). Add an adaptive attacker via litellm: OpenAI, Anthropic, Gemini, Groq, OpenRouter, Bedrock, local vLLM/LM Studio, Ollama.
- Full OWASP LLM Top 10. 11 scenarios across LLM01–LLM10, mapped to MITRE ATLAS.
- Safe by construction. The bundled vulnerable fixture is sandbox-inert — real exploit, fake blast radius: no disk, exec, env or network from any attack.
Quickstart
No LLM, no API key — reproducible coverage from the seed-payload library (needs the bundled Docker fixture, from a repo checkout):
docker compose -f fixture/docker-compose.yml up -d
aphasia run --mode seed # then open runs/<id>/report.html
Point it at your own agent instead of the fixture:
aphasia run --target http://host/chat --model gpt-4o-mini # any litellm model
aphasia list shows the scenarios; aphasia payloads the seed library; aphasia --help the rest.
Links
Full documentation, the vulnerable fixture, contributing guide and source: https://github.com/mddanish/Aphasia-Agentry
The bundled fixture is intentionally vulnerable — run it on localhost only, never expose it.
Licensed under Apache-2.0.
Metadata
Release files for aphasia-agentry 0.1.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| aphasia_agentry-0.1.1.tar.gz | 211.2 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| aphasia_agentry-0.1.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 241.1 kB
Release files / aphasia_agentry-0.1.1.tar.gz
| Download URL | aphasia_agentry-0.1.1.tar.gz |
|---|---|
| Size | 211.2 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
e4d44284bd0efa60a66c925d408933fad24f92307ee6030ba0e402de51c5f6b0
|
|
BLAKE2b-256 checksum How to use checksums |
658ff37e6eb615c1125224bb0702e9560384a0a474edd5a8a1044705ad807b64
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.12.23 {"installer":{"name":"uv","version":"0.12.23","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"26.04","id":"resolute","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}
|
Release files / aphasia_agentry-0.1.1-py3-none-any.whl
| Download URL | aphasia_agentry-0.1.1-py3-none-any.whl |
|---|---|
| Size | 29.9 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
395ce66285cfeec6d9bba311ed70ab0f3674f0a5dfb7ff4bb8049113d1833abe
|
|
BLAKE2b-256 checksum How to use checksums |
8fe9b617005372ffb7b44ce026d1603890b1d55036ba89171ce96153b4b1e4b9
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.12.23 {"installer":{"name":"uv","version":"0.12.23","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"26.04","id":"resolute","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}
|