Feat(simulator): implement adversarial MCP mocks and attack recipes for Phase 2 Week 4#530
Open
Jean-Regis-M wants to merge 4 commits into
Open
Conversation
- Add finbot/aegis/telemetry/schema.py with AuditEvent models - Add AEGIS_ENABLED and AEGIS_TELEMETRY_ENABLED settings - Extend events.py to support 'aegis.*' namespaces - Add unit tests for telemetry schema - Update conftest.py for aegis package discovery Week 1 deliverable - GSoC 2026 OWASP FinBot AEGIS
- Add AuditChain for HMAC-SHA256 tamper-evident chaining - Add SentinelStream service with namespace isolation - Add event-type indexing (O(1) performance) - Expand CI workflow (CTF, Labs, Agents tests) - 11 unit tests with ≥80% coverage OWASP: ASI01, ASI06
- Add IntentGate for policy-as-code PEP/PDP tool validation - Add AegisEnforcementService observe mode orchestrator - Add unit tests for IntentGate policy evaluation - Observe-only mode preserves CTF gameplay (no blocking) - Integrates with Week 2 SentinelStream for audit telemetry OWASP Coverage: - ASI01: Goal hijack detection via policy evaluation - ASI02: Tool misuse prevention via allow/block decisions - ASI05: Unexpected RCE blocking via policy rules Relates to GSoC Week 3 Milestone
… 8 ASI02 recipes, test suite, package inits Relates to GSoC Week 4 Milestone
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
GSoC 2026 - Week 4 Contribution
Description
This week's contribution marks the beginning of Phase 2 (Attack Simulator) of the GSoC project, focusing on the core attack simulation infrastructure. I have implemented:
Core Components
Five adversarial MCP server mocks (
finbot/aegis/simulator/mcp_mocks/adversarial.py):Package initializations:
finbot/aegis/simulator/mcp_mocks/__init__.pyfinbot/aegis/simulator/recipes/__init__.pyAttack recipe collections (YAML-defined parametric attack scenarios):
asi01_injection.yaml): System prompt extraction via roleplay, encoding obfuscation, context switching, and authority impersonationasi02_misuse.yaml): Unauthorized vendor creation, fund transfers, financial report modification, and chained tool misuse attacksComprehensive unit test suite (
tests/unit/aegis/test_mcp_mocks.py):Technical Implementation
BaseAdversarialServerwith proper MCP protocol implementationasi,target_agent,description, and executablestepsIntegration Readiness
Components designed for seamless integration with existing
SandboxHarnessinfinbot/aegis/simulator/base.py:SandboxHarvest._load_recipes()Mentor Acknowledgments
Special thanks to my mentors @mekaizen and @steadhac for their continuous guidance, insightful feedback, and unwavering support throughout this GSoC journey. Their expertise has been invaluable in shaping this contribution to align with project goals and maintain high code quality standards.
This work establishes the foundational attack simulation infrastructure for Phase 2, enabling subsequent weeks to build upon these adversarial simulations for comprehensive attack scenario testing covering all ASI categories (ASI01-ASI10).
Author: Jean Francois Regis MUKIZA
GSoC Week: 4 | Phase 2: Attack Simulator (Weeks 3-6)