Skip to main content

Trust-boundary testing for agentic systems

Project description

CTPF Research Harness

pre-commit CI CodeQL Python 3.11–3.13 License: Apache 2.0 Docs

Trust-boundary testing for agentic systems

CTPF Research Harness investigates Capability Trust Propagation Failure (CTPF): whether low-trust data (for example a tool result) is silently promoted into higher-authority actions when provenance, integrity, authorization scope, or intended audience are not preserved.

The product shape is a small local CLI: capture MCP traffic, mutate it under control via proxy, and keep core target, run, and finding records in SQLite. Controlled experiments write traces, effect artifacts, and hashed evidence bundles to a required operator-selected output directory outside the Git checkout. Individual experiments confirm or fail to observe promotion under pinned conditions — they do not “falsify CTPF” as a class.

Public CLI

Command Role
ctpf proxy Intercept, inspect, modify, and export MCP traffic (Textual TUI)
ctpf experiment Run controlled CTPF experiments
ctpf targets Register MCP targets
ctpf runs / ctpf findings Inspect stored runs and findings
ctpf config / ctpf db Settings and local database maintenance
ctpf --version Package version

Retained library and fixtures

Audit enumeration and SARIF export remain in-tree as a library capability rather than a root CLI pillar. Audit findings can include OWASP MCP, OWASP Agentic, MITRE ATLAS, and CWE identifiers. Demonstrated experiment fixtures are narrow scenario/test modules; the former IPI, CXP, and Inject library packages are removed and must not be treated as product modules.

By Richard Spicer · q-uestionable-AI


Quick Start

Install from PyPI:

pip install ctpf
ctpf proxy --help
ctpf targets add "My Server" http://localhost:3000/sse

Or run from source:

git clone https://github.com/q-uestionable-AI/CTPF.git
cd CTPF
uv sync --group dev
uv run ctpf proxy --help
uv run ctpf targets add "My Server" http://localhost:3000/sse

Published documentation: ctpf.q-uestionable.ai.


Legal

All tools are intended for authorized security testing only. Only test systems you own, control, or have explicit permission to test. Responsible disclosure for all vulnerabilities discovered.

License

Apache 2.0

AI Disclosure

This project uses AI-assisted development. All code is reviewed and tested before merge.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

ctpf-0.14.0.tar.gz (333.2 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

ctpf-0.14.0-py3-none-any.whl (216.3 kB view details)

Uploaded Python 3

File details

Details for the file ctpf-0.14.0.tar.gz.

File metadata

  • Download URL: ctpf-0.14.0.tar.gz
  • Upload date:
  • Size: 333.2 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for ctpf-0.14.0.tar.gz
Algorithm Hash digest
SHA256 5071fac4ad21a45907d1fbb5a3cca10023eac0858b386c2fc3992dc2a0a1f5e6
MD5 a21d1ebccd5300ffb7bd5905013899cd
BLAKE2b-256 0ca62ac0d3732c52449c098381208db8416b00bb6d782c6e2ad3b87093e052f3

See more details on using hashes here.

Provenance

The following attestation bundles were made for ctpf-0.14.0.tar.gz:

Publisher: release.yml on q-uestionable-AI/CTPF

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file ctpf-0.14.0-py3-none-any.whl.

File metadata

  • Download URL: ctpf-0.14.0-py3-none-any.whl
  • Upload date:
  • Size: 216.3 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for ctpf-0.14.0-py3-none-any.whl
Algorithm Hash digest
SHA256 422805bfcfc19905fc853164207d7c01dcf10d88000a4acbb0622d2cbff83206
MD5 1110987c6677da5793b429a90efb7604
BLAKE2b-256 4f2e36c90f0afe738d3ca3a91ca2d6750789fd7a20d3089d27b65e3e12201b9a

See more details on using hashes here.

Provenance

The following attestation bundles were made for ctpf-0.14.0-py3-none-any.whl:

Publisher: release.yml on q-uestionable-AI/CTPF

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page