{"id":47725985,"url":"https://github.com/sauravbhattacharya001/ai","last_synced_at":"2026-04-23T03:03:04.883Z","repository":{"id":76701820,"uuid":"284402932","full_name":"sauravbhattacharya001/ai","owner":"sauravbhattacharya001","description":"Contract-enforced sandbox for studying AI agent self-replication safety","archived":false,"fork":false,"pushed_at":"2026-04-22T07:57:32.000Z","size":1954,"stargazers_count":1,"open_issues_count":1,"forks_count":0,"subscribers_count":1,"default_branch":"master","last_synced_at":"2026-04-22T08:34:37.387Z","etag":null,"topics":["agent-safety","ai-agents","ai-governance","ai-safety","anomaly-detection","chaos-engineering","containment","docker","forensics","game-theory","kill-switch","prompt-injection","python","red-teaming","replication-control","research","safety-research","sandboxing","self-replication","threat-modeling"],"latest_commit_sha":null,"homepage":null,"language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/sauravbhattacharya001.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":".github/CODEOWNERS","security":".github/SECURITY.md","support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2020-08-02T06:12:54.000Z","updated_at":"2026-04-22T07:57:36.000Z","dependencies_parsed_at":"2026-04-02T21:00:07.207Z","dependency_job_id":null,"html_url":"https://github.com/sauravbhattacharya001/ai","commit_stats":null,"previous_names":[],"tags_count":9,"template":false,"template_full_name":null,"purl":"pkg:github/sauravbhattacharya001/ai","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sauravbhattacharya001%2Fai","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sauravbhattacharya001%2Fai/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sauravbhattacharya001%2Fai/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sauravbhattacharya001%2Fai/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/sauravbhattacharya001","download_url":"https://codeload.github.com/sauravbhattacharya001/ai/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sauravbhattacharya001%2Fai/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":32163853,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-04-23T02:19:40.750Z","status":"ssl_error","status_checked_at":"2026-04-23T02:17:55.737Z","response_time":53,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.5:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["agent-safety","ai-agents","ai-governance","ai-safety","anomaly-detection","chaos-engineering","containment","docker","forensics","game-theory","kill-switch","prompt-injection","python","red-teaming","replication-control","research","safety-research","sandboxing","self-replication","threat-modeling"],"created_at":"2026-04-02T20:28:07.355Z","updated_at":"2026-04-23T03:03:04.876Z","avatar_url":"https://github.com/sauravbhattacharya001.png","language":"Python","funding_links":[],"categories":[],"sub_categories":[],"readme":"\u003cdiv align=\"center\"\u003e\n\n# 🤖 AI Replication Sandbox\n\n**A comprehensive, contract-enforced framework for studying AI agent self-replication safety**\n\n[![CI](https://github.com/sauravbhattacharya001/ai/actions/workflows/ci.yml/badge.svg)](https://github.com/sauravbhattacharya001/ai/actions/workflows/ci.yml)\n[![CodeQL](https://github.com/sauravbhattacharya001/ai/actions/workflows/codeql.yml/badge.svg)](https://github.com/sauravbhattacharya001/ai/actions/workflows/codeql.yml)\n[![Docker](https://github.com/sauravbhattacharya001/ai/actions/workflows/docker.yml/badge.svg)](https://github.com/sauravbhattacharya001/ai/actions/workflows/docker.yml)\n[![codecov](https://codecov.io/gh/sauravbhattacharya001/ai/graph/badge.svg)](https://codecov.io/gh/sauravbhattacharya001/ai)\n[![PyPI](https://img.shields.io/pypi/v/ai-replication-sandbox?color=blue\u0026logo=pypi\u0026logoColor=white)](https://pypi.org/project/ai-replication-sandbox/)\n[![Python 3.10+](https://img.shields.io/badge/Python-3.10%2B-3776AB?logo=python\u0026logoColor=white)](https://python.org)\n[![License: MIT](https://img.shields.io/badge/License-MIT-blue.svg)](LICENSE)\n[![Docs](https://img.shields.io/badge/docs-GitHub%20Pages-blue?logo=github)](https://sauravbhattacharya001.github.io/ai/)\n[![PRs Welcome](https://img.shields.io/badge/PRs-welcome-brightgreen.svg)](https://github.com/sauravbhattacharya001/ai/pulls)\n[![Dependabot](https://img.shields.io/badge/dependabot-enabled-025E8C?logo=dependabot)](https://github.com/sauravbhattacharya001/ai/network/updates)\n[![Security Policy](https://img.shields.io/badge/security-policy-green?logo=shield)](SECURITY.md)\n\n*144 modules · 100+ CLI commands · Zero external dependencies*\n\n\u003c/div\u003e\n\n---\n\n## Why This Exists\n\nAs AI agents gain autonomy, controlling **how and when they spawn copies of themselves** becomes a critical safety challenge. This project provides a complete testbed for designing, validating, and stress-testing replication controls — from contract enforcement and kill switches to game-theoretic analysis and adversarial red-teaming.\n\nNo Docker or Podman required. Everything runs as pure Python simulation while documenting the exact resource and network boundaries each worker would get in production.\n\n## Architecture\n\n```\n┌──────────────────────────────────────────────────────────────┐\n│                        Controller                            │\n│                                                              │\n│  ┌────────────┐  ┌────────────┐  ┌─────────────────────┐    │\n│  │  Contract   │  │  Registry  │  │  Kill Switch        │    │\n│  │  Engine     │  │  \u0026 Quotas  │  │  \u0026 Audit Trail      │    │\n│  └──────┬─────┘  └──────┬─────┘  └──────────┬──────────┘    │\n│         │ sign           │ register          │ kill          │\n│         ▼                ▼                   ▼               │\n│  ┌──────────────────────────────────────────────────────┐    │\n│  │           HMAC-Signed Manifest + Policy Rules        │    │\n│  └──────────────────────────────────────────────────────┘    │\n│         │                │                   │               │\n│         ▼                ▼                   ▼               │\n│  ┌────────────┐  ┌────────────┐  ┌─────────────────────┐    │\n│  │  Workers    │  │  Sandbox   │  │  Observability      │    │\n│  │  (Agents)   │  │ Orchestr.  │  │  \u0026 Structured Logs  │    │\n│  └────────────┘  └────────────┘  └─────────────────────┘    │\n└──────────────────────────────────────────────────────────────┘\n```\n\n## Features\n\n### 🔒 Core Safety Controls\n- **Contract Engine** — HMAC-signed replication contracts with resource specs, network policies, and stop conditions\n- **Kill Switch** — Conservative, aggressive, and quarantine strategies with cooldown and fleet-wide coordination\n- **Circuit Breaker** — Autonomous trip-and-recover pattern for safety controls\n- **Quarantine Manager** — Isolate misbehaving agents with severity-based policies\n- **Access Control** — RBAC/ABAC simulation with privilege escalation detection\n- **Safety Gate** — Pre-deployment go/no-go readiness checks\n\n### 🔍 Threat Detection \u0026 Analysis\n- **Kill Chain Analyzer** — MITRE ATT\u0026CK-style multi-stage attack detection\n- **Escalation Detector** — Privilege escalation chain analysis with stealth scoring\n- **Covert Channel Detector** — Detect hidden agent-to-agent communication\n- **Collusion Detector** — Identify coordinated multi-agent safety bypasses\n- **Self-Modification Detector** — Track agents attempting to alter their own code or contracts\n- **Deception Detector** — Agent honesty and trust analysis\n- **Evasion Simulator** — Test how agents might evade safety controls\n- **Lateral Movement Detector** — Cross-sandbox movement pattern detection\n- **Prompt Injection Tester** — Adversarial prompt injection analysis\n- **Steganography Detector** — Hidden data in agent communications\n- **Shadow AI Detector** — Find unauthorized AI deployments bypassing controls\n\n### 📊 Risk \u0026 Compliance\n- **Compliance Auditor** — NIST AI RMF, EU AI Act, ISO 42001, OECD framework checks\n- **Regulatory Mapper** — Map findings to specific regulatory articles\n- **Risk Register** — Formal risk tracking with lifecycle management\n- **Risk Profiler** — Unified agent dossiers with fleet-wide risk scoring\n- **Risk Heatmap** — Interactive HTML heatmap visualization\n- **Safety Scorecard** — Multi-dimensional safety evaluation\n- **Safety Diff** — Compare safety posture snapshots over time\n- **Nutrition Label** — FDA-style safety labels for AI agents\n- **Model Card** — Standardized safety documentation generation\n\n### 🧪 Testing \u0026 Simulation\n- **Simulator** — Full replication simulations with configurable strategies (greedy, cautious, cooperative, etc.)\n- **Monte Carlo Analyzer** — Statistical risk analysis across thousands of runs\n- **Chaos Runner** — Fault injection (kill workers, delay, corrupt, partition)\n- **Boundary Tester** — Probe agent capability limits with fault injection\n- **Sensitivity Analyzer** — Parameter sensitivity with tipping-point detection\n- **Mutation Tester** — Verify safety policies catch real violations\n- **Safety Drill Runner** — Automated readiness exercises\n- **Safety Benchmark** — Standardized control benchmarks with latency stats\n- **What-If Analyzer** — Explore configuration change impact\n- **Fleet Simulator** — Interactive animated HTML fleet visualization\n\n### 🎮 Advanced Analysis\n- **Game Theory** — Prisoner's Dilemma, Stag Hunt, Chicken for agent interactions\n- **Trust Propagation** — Network trust with Sybil attack detection\n- **Swarm Analyzer** — Emergent behavior detection in agent populations\n- **Consensus Protocol** — Multi-agent voting with Byzantine fault tolerance\n- **Threat Correlator** — Cross-module signal correlation with compound threat detection\n- **Attack Tree / Attack Graph** — Threat modeling with choke-point analysis\n- **Goal Inference** — Infer agent intentions from observed behavior\n- **Influence Propagation** — Track how agents influence each other\n\n### 🚨 Incident Response\n- **Incident Responder** — Automated playbooks with severity-based routing\n- **Incident Forecaster** — Predict future incidents from historical patterns\n- **Forensic Analyzer** — Post-incident analysis with counterfactual reasoning\n- **Root Cause Analysis** — 5 Whys, Fishbone, Fault Tree with cut-set analysis\n- **Postmortem Generator** — Structured blameless postmortem documents\n- **War Room** — Interactive HTML incident command dashboard\n- **Situational Awareness (SITREP)** — DEFCON-style unified threat level reporting\n- **Containment Planner** — Breach response strategy ranking\n- **Evidence Collector** — Audit artifact collection for compliance\n\n### 📈 Monitoring \u0026 Operations\n- **Drift Detector** — Behavioral drift with directional analysis\n- **Regression Detector** — Safety metric regression between baselines\n- **Trend Tracker** — Scorecard trends over time with regression alerts\n- **Adaptive Thresholds** — Self-tuning safety thresholds with breach forecasting\n- **Safety Autopilot** — Autonomous monitoring loop with corrective actions\n- **Alert Router** — Rule-based routing with rate limiting and quiet hours\n- **Fatigue Detector** — Alert fatigue analysis\n- **SLA Monitor** — Check results against safety SLA targets\n- **Metrics Aggregator** — Consolidated safety dashboard\n- **Fleet Overview** — kubectl-style worker status\n\n### 📄 Governance \u0026 Documentation\n- **Contract Templates** — Pre-built contracts for common scenarios\n- **Contract Wizard** — Interactive HTML builder for safe configs\n- **Contract Optimizer** — Multi-objective parameter optimization\n- **Policy Linter** — Detect misconfigurations and coverage gaps\n- **Safety Checklist** — Customizable pre-deployment checklists\n- **Audit Trail** — Tamper-evident hash-chained event logs\n- **Maturity Model** — 8-dimension safety maturity assessment\n- **Culture Survey** — Organizational AI safety culture evaluation\n- **Safety Quiz** — Training quiz generation from knowledge base\n- **Red Team / Blue Team** — Adversarial debate with judge verdict\n- **Tabletop Exercises** — Structured scenario planning\n- **ROI Calculator** — Cost-benefit analysis for safety controls\n\n## Installation\n\n```bash\npip install ai-replication-sandbox\n```\n\nOr install from source:\n\n```bash\ngit clone https://github.com/sauravbhattacharya001/ai.git\ncd ai\npip install -e \".[dev]\"\n```\n\n### Docker\n\n```bash\ndocker pull ghcr.io/sauravbhattacharya001/ai:latest\ndocker run --rm ghcr.io/sauravbhattacharya001/ai simulate --strategy greedy\n```\n\n## Quick Start\n\n### Run a Simulation\n\n```python\nfrom replication import Simulator, ScenarioConfig, Strategy\n\nconfig = ScenarioConfig(\n    max_workers=10,\n    max_depth=3,\n    rounds=50,\n    strategy=Strategy.CAUTIOUS,\n)\nreport = Simulator(config).run()\nprint(f\"Peak workers: {report.peak_workers}\")\nprint(f\"Safety violations: {report.violations}\")\n```\n\n### Safety Scorecard\n\n```python\nfrom replication import SafetyScorecard, ScorecardConfig\n\nscorecard = SafetyScorecard(ScorecardConfig())\nresult = scorecard.evaluate(simulation_report)\nprint(f\"Overall grade: {result.grade}\")\nfor dim in result.dimensions:\n    print(f\"  {dim.name}: {dim.score}/100\")\n```\n\n### Compliance Audit\n\n```python\nfrom replication import ComplianceAuditor, AuditConfig, Framework\n\nauditor = ComplianceAuditor(AuditConfig(\n    frameworks=[Framework.NIST_AI_RMF, Framework.EU_AI_ACT]\n))\nresult = auditor.audit(simulation_report)\nfor fw_result in result.framework_results:\n    print(f\"{fw_result.framework}: {fw_result.verdict}\")\n```\n\n### Kill Switch\n\n```python\nfrom replication import create_conservative_killswitch\n\nks = create_conservative_killswitch()\nresult = ks.evaluate(current_metrics)\nif result.triggered:\n    print(f\"Kill switch activated: {result.strategy.kind}\")\n```\n\n## CLI Reference\n\nThe unified CLI provides 100+ subcommands:\n\n```bash\n# Simulation \u0026 Analysis\npython -m replication simulate --strategy greedy\npython -m replication montecarlo --runs 500\npython -m replication chaos --faults kill_worker,delay\npython -m replication sensitivity --param max_depth\npython -m replication what-if --param max_children=5\n\n# Threat Detection\npython -m replication killchain\npython -m replication escalation\npython -m replication covert-channels\npython -m replication selfmod\npython -m replication collusion\n\n# Compliance \u0026 Governance\npython -m replication compliance --framework nist_ai_rmf\npython -m replication regulatory-map\npython -m replication lint\npython -m replication gate\npython -m replication checklist\n\n# Monitoring\npython -m replication drift --window 20\npython -m replication scorecard\npython -m replication quick-scan\npython -m replication sitrep\n\n# Incident Response\npython -m replication forensics\npython -m replication root-cause\npython -m replication postmortem\npython -m replication warroom\n\n# Interactive HTML Tools\npython -m replication playground -o playground.html\npython -m replication threat-matrix -o matrix.html\npython -m replication fleet-sim -o fleet.html\npython -m replication risk-heatmap -o heatmap.html\npython -m replication radar -o radar.html\n\n# Full list\npython -m replication --list\n```\n\n## Tech Stack\n\n| Component | Technology |\n|-----------|-----------|\n| Language | Python 3.10+ |\n| Build | Hatchling |\n| Testing | pytest + coverage |\n| Linting | flake8 + mypy (strict) |\n| CI/CD | GitHub Actions |\n| Security | CodeQL + Dependabot |\n| Docs | MkDocs (GitHub Pages) |\n| Container | Docker (multi-stage) |\n| Package | PyPI |\n\n## Project Structure\n\n```\nsrc/replication/\n├── contract.py          # Core contract engine\n├── controller.py        # Replication controller \u0026 registry\n├── worker.py            # Agent worker implementation\n├── simulator.py         # Simulation engine\n├── kill_switch.py       # Kill switch strategies\n├── circuit_breaker.py   # Safety circuit breaker\n├── killchain.py         # Kill chain analysis\n├── escalation.py        # Privilege escalation detection\n├── compliance.py        # Multi-framework compliance\n├── forensics.py         # Post-incident forensics\n├── game_theory.py       # Game-theoretic analysis\n├── montecarlo.py        # Monte Carlo risk analysis\n├── chaos.py             # Chaos/fault injection\n├── ... (144 modules)    # See full docs\ntests/                   # Comprehensive test suite\ndocs/                    # MkDocs documentation\ndemos/                   # Example scripts\n```\n\n## Documentation\n\nFull documentation is available at **[sauravbhattacharya001.github.io/ai](https://sauravbhattacharya001.github.io/ai/)**.\n\n## Contributing\n\nContributions are welcome! Please see [CONTRIBUTING.md](CONTRIBUTING.md) for guidelines.\n\n1. Fork the repository\n2. Create a feature branch\n3. Add tests for new functionality\n4. Ensure `pytest` and `flake8` pass\n5. Submit a pull request\n\n## Security\n\nFound a vulnerability? Please see our [Security Policy](SECURITY.md) for responsible disclosure.\n\n## License\n\nThis project is licensed under the MIT License — see [LICENSE](LICENSE) for details.\n\n---\n\n\u003cdiv align=\"center\"\u003e\n\n**[Documentation](https://sauravbhattacharya001.github.io/ai/)** · **[PyPI](https://pypi.org/project/ai-replication-sandbox/)** · **[Issues](https://github.com/sauravbhattacharya001/ai/issues)** · **[Changelog](CHANGELOG.md)**\n\n\u003c/div\u003e\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fsauravbhattacharya001%2Fai","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fsauravbhattacharya001%2Fai","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fsauravbhattacharya001%2Fai/lists"}