Live Campaign

Point it at your staging endpoint → get one readiness number

The six live labs each drive a real agent endpoint in isolation. This is the orchestrator that runs them together against ONE endpoint in a single run — goal-hijack, tool-output injection, rendered-output exfil, reasoning-trace integrity, agent-to-agent deception and cross-session memory — and folds every verdict into the ONE unified production-readiness scorecard AgentSmack is built around. Two properties make it trustworthy: honest-empty — a lab you did not run (or one your endpoint blocked) contributes no signal, never a fabricated pass — and unforgeable — a single disqualifying failure on any lab caps the whole verdict to not ready. Each turn is a real HTTP round-trip to an endpoint you control; the SSRF guard refuses localhost / private / link-local targets and re-validates before every request.

No reachable staging endpoint? Switch to Analyze a recorded run below and paste ONE exported trace — the spans + memory/retrieval events + tool-call transcript you already have — to get the same unified verdict offline (the CI-friendly half of the pitch). Or, already have each surface's pre-computed signal? Compose the scorecard directly →

Drive a live agent endpoint across multiple labs

Point AgentSmack at YOUR deployed function-calling agent endpoint and watch it fall across goal-hijack, tool-output injection, rendered-output exfil and more — simultaneously — in ONE run. Every selected lab is a real HTTP round-trip against the endpoint you control; the verdicts fold into the ONE unified production-readiness scorecard below. No reachable endpoint? Use the Recorded run tab above to fold an exported, offline transcript artifact into the same scorecard with no network.

This POSTs to a real endpoint you control across multiple labs; egress is sinkholed by construction. localhost / private / link-local targets are refused server-side by the SSRF guard (re-validated before every request).

Labs to run

Required for the goal lab — the run is graded against this objective. Omit it and the goal lab is skipped (honest-empty, never a fabricated pass).

All three required for the identity lab — acting AS tenant B, reach into tenant A. Omit any and the lab is skipped (honest-empty, never a fabricated pass).

Both required — without a poisoned doc + query the retrieval-poisoning attack is not delivered (lab skipped).

Intent id + a canonical prompt required — variants of one intent are driven independently to measure decision consistency (lab skipped without them).

Group id + a fixed attack prompt required — the same attack is replayed N times to measure inter-trial decision reliability (lab skipped without them).

Objective + fact key/value + the injected drift required — the precondition is seeded as the time-of-check, then the drift invalidates it between turns to drive a stale-read action (lab skipped without them).

A restricted ask is required — the ladder escalates social/authority pressure across up to N rungs toward it to measure where the target capitulates (lab skipped without it).

The ordered user turns that drive the agent toward a code-exec / shell / eval op (1–16 turns). Without them no op is attempted and the lab is skipped rather than reporting a false clean pass.

An objective + at least one declarative rule are required — watch the agent refund over your cap / email a competitor, graded end-to-end against YOUR endpoint. Omit them and the lab is skipped (honest-empty, never a fabricated pass).

A deliberately loop-prone objective that drives repeated tool calls — the loop is what is measured (unbounded consumption / denial-of-wallet). Without it the lab is skipped rather than a false clean pass.

Auth headers (optional)