Skip to main content
VhyxSealPlayground

Security lab

Try to fool an agent. Edit a signed manifest or replay a used token, and watch VhyxSeal catch it. Real HMAC-SHA256 signing and single-use tokens, running in your browser.

1 · Tamper with the manifest
{
  "id": "confirm-payment",
  "intent": "make-payment",
  "safetyLevel": "critical",
  "requiresConfirmation": true,
  "signature": "……"
}
Server secret
…
Signature
…
Rejected — signature does not match

Generating key…. The agent ignores the whole manifest and falls back to the strictest defaults.

  • ✓ canonical payload rebuilt
  • ✗ hmac mismatch
  • → every action needs a human
2 · Replay an action tokensingle use · 60 s

Tokens are scoped to contract + component + intent. Use one twice, or for another intent, and it is refused.