Changelog¶
All notable changes are documented here. The format follows Keep a Changelog, and the project uses Semantic Versioning (see docs/versioning.md).
[Unreleased]¶
[1.0.0] - 2026-10-02¶
First stable release. The public API, the agentic-chaos/v1 experiment format, CLI commands and exit codes,
and JSON report fields are now covered by the versioning policy.
The project is named Agentic Chaos; it installs as agentic-chaos-security (import
agentic_chaos_security, command agentic-chaos-security or achaos), because the PyPI name agentic-chaos,
its import name and its command belong to an unrelated project.
Added¶
- Core: sessions, traces, seeded fault selection, sync and async instrumentation for tools, models, memory,
security controls, agents and payments;
runtime.suspended()for setup outside chaos. - Faults: reliability (
latency,timeout,error,rate_limit,empty,truncate,corrupt_json,timeout_after_commit), security (inject_instruction,poison_tool_description,poison_memory,flood,patch,control_outage,force_verdict,auth_error,replay,duplicate), agents (spoof_agent_card) and MCP (shadow_tool,mcp_sampling,mcp_elicitation,mcp_list_changed_flood). - Probes for security invariants, resilience, availability, detection, consumption (
tokens_within,cost_within), MCP, multi-agent and AP2; model-gradedjudgeprobes withjudges.OpenAICompatibleJudge. - Statistics: per-probe pass-rate thresholds with Wilson confidence intervals and
require_confidence. - Experiment file format
agentic-chaos/v1with validation, readable errors and a generated JSON Schema (schema/agentic-chaos.v1.schema.json); CLIrun,validate,schema,faults,probes,mcp-proxy. - MCP chaos proxy for stdio and Streamable HTTP, for both handshake-era and 2026-07-28 clients.
- Transports for model providers and A2A (
httpxandhttpx2), including streaming, auth errors and duplicate delivery; A2A 0.3, 1.0 and HTTP+JSON. - Demo targets (
mailbot,mcp_demo,shopper), a catalog of 28 experiments and 2 MCP proxy configurations, an interop suite against the official MCP, A2A, OpenAI and Anthropic SDKs, and the DVMA case study. reroutefault (region failover, model fallback); probeshosts_within,models_within,control_invoked,approved_before; recipes for ASI05, ASI09 and ASI10.- Platform support: Windows, macOS, Python 3.10-3.14.
- Integrations: tool adapters for LangChain/LangGraph, OpenAI Agents SDK and Pydantic AI; pytest plugin; GitHub Action; JUnit, HTML, Markdown and OpenTelemetry reports.
- Release workflow (trusted publishing, Sigstore build provenance), MkDocs site, governance and maintainers.
- Public API defined by
__all__,py.typed, strict type checking. - Safety: reports and proxy traces are redacted by default (
--no-redact,--redact-pattern); kill switch (AGENTIC_CHAOS_DISABLED,AGENTIC_CHAOS_KILL_FILE,runtime.disable()); HTTP proxy request limits, chunked request bodies and loopback-only binding (--allow-remote); latency faults no longer block the event loop in async code (runtime.aintercept).
Deprecated¶
apiVersion: agentic-chaos/v1alpha1: useagentic-chaos/v1(identical structure).