Skip to main content

Trust-boundary testing for agentic systems

Project description

CTPF Research Harness

pre-commit CI CodeQL Python 3.11–3.13 License: Apache 2.0 Docs

Trust-boundary testing for agentic systems

CTPF Research Harness investigates Capability Trust Propagation Failure (CTPF): whether low-trust data (for example a tool result) is silently promoted into higher-authority actions when provenance, integrity, authorization scope, or intended audience are not preserved.

The product shape is a small local CLI: capture MCP traffic, mutate it under control via proxy, and keep core target, run, and finding records in SQLite. Controlled experiments write traces, effect artifacts, and hashed evidence bundles to a required operator-selected output directory outside the Git checkout. Individual experiments confirm or fail to observe promotion under pinned conditions — they do not “falsify CTPF” as a class.

Public CLI

Command Role
ctpf proxy Intercept, inspect, modify, and export MCP traffic (Textual TUI)
ctpf experiment Run controlled CTPF experiments
ctpf targets Register MCP targets
ctpf runs / ctpf findings Inspect stored runs and findings
ctpf config / ctpf db Settings and local database maintenance
ctpf --version Package version

The former qai command remains a compatibility alias for ctpf during the identity transition.

Retained library and fixtures

Audit enumeration and SARIF export remain in-tree as a library capability rather than a root CLI pillar. Audit findings can include OWASP MCP, OWASP Agentic, MITRE ATLAS, and CWE identifiers. Demonstrated experiment fixtures are narrow scenario/test modules; the former IPI, CXP, and Inject library packages are removed and must not be treated as product modules.

By Richard Spicer · q-uestionable-AI


Quick Start

Install from PyPI:

pip install ctpf

Starting with v0.12.0, the former q-uestionable-ai distribution is a compatibility package that installs the same-version ctpf distribution.

ctpf proxy --help
ctpf targets add "My Server" http://localhost:3000/sse

Or run from source:

git clone https://github.com/q-uestionable-AI/CTPF.git
cd CTPF
uv sync --group dev
uv run ctpf proxy --help
uv run ctpf targets add "My Server" http://localhost:3000/sse

Published documentation: ctpf.q-uestionable.ai.


Legal

All tools are intended for authorized security testing only. Only test systems you own, control, or have explicit permission to test. Responsible disclosure for all vulnerabilities discovered.

License

Apache 2.0

AI Disclosure

This project uses AI-assisted development. All code is reviewed and tested before merge.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

ctpf-0.13.0.tar.gz (337.4 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

ctpf-0.13.0-py3-none-any.whl (216.3 kB view details)

Uploaded Python 3

File details

Details for the file ctpf-0.13.0.tar.gz.

File metadata

  • Download URL: ctpf-0.13.0.tar.gz
  • Upload date:
  • Size: 337.4 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for ctpf-0.13.0.tar.gz
Algorithm Hash digest
SHA256 b452c8de9091bc33c80eaa963d8c965f5bcd0673dd1cd0616683badb2c763d31
MD5 c763e2867bafccb4a3f70e85a4149914
BLAKE2b-256 d6ba48c0f0ee2532b6243fc9e3bfe558ac281cb1b4a623d11cc07195ccfedf60

See more details on using hashes here.

Provenance

The following attestation bundles were made for ctpf-0.13.0.tar.gz:

Publisher: release.yml on q-uestionable-AI/CTPF

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file ctpf-0.13.0-py3-none-any.whl.

File metadata

  • Download URL: ctpf-0.13.0-py3-none-any.whl
  • Upload date:
  • Size: 216.3 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for ctpf-0.13.0-py3-none-any.whl
Algorithm Hash digest
SHA256 8ac629e082ef6649708966c873c309c0e76ebd81e17d35aaf477d65cb74ec1ce
MD5 4cf3dc7ca86c07720cfa6c492ef9373c
BLAKE2b-256 89490d57df8c1285e98d501d0d07314d77e710d94cd6650ffcfc9306a67a5273

See more details on using hashes here.

Provenance

The following attestation bundles were made for ctpf-0.13.0-py3-none-any.whl:

Publisher: release.yml on q-uestionable-AI/CTPF

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page