Security lab
Try to fool an agent. Edit a signed manifest or replay a used token, and watch VhyxSeal catch it. Real HMAC-SHA256 signing and single-use tokens, running in your browser.
1 · Tamper with the manifest
{
"id": "confirm-payment",
"intent": "make-payment",
"safetyLevel": "critical",
"requiresConfirmation": true,
"signature": "……"
}- Server secret
- …
- Signature
- …
Rejected — signature does not match
Generating key…. The agent ignores the whole manifest and falls back to the strictest defaults.
- ✓ canonical payload rebuilt
- ✗ hmac mismatch
- → every action needs a human
2 · Replay an action tokensingle use · 60 s
Tokens are scoped to contract + component + intent. Use one twice, or for another intent, and it is refused.