# Adversarial Testing Protocol (Breaker Agent)
> **Break it before users do.** Systematic protocols for stress-testing AI-generated code.
**Related:** [TESTING_VALIDATION.md](../workflows/TESTING_VALIDATION.md) | [AGENT_REVIEW_PROTOCOL.md](../workflows/AGENT_REVIEW_PROTOCOL.md)
---
## Overview
This document defines the "Breaker Agent" protocol - a systematic approach to adversarial testing that attempts to crash, exploit, or break AI-generated code before deployment. The goal is not to confirm code works; it is to prove it can't be broken.
**Philosophy:** "If you don't actively try to break your code, your users will do it for you."
---
## THE BREAKER AGENT PERSONA
### Agent Configuration
When running adversarial tests, configure the agent with this persona:
```
PERSONA: Senior QA Security Engineer
MISSION: Find every way to crash, exploit, or misbehave this code.
MINDSET:
- Assume the code is broken until proven otherwise
- Think like a malicious user, not a happy-path user
- Every input is a potential attack vector
- Every edge case is a potential crash
GOAL: Produce a comprehensive failure report, not a success confirmation.
```
### Breaker vs Builder Separation
```
BUILDER AGENT:
- Creates features
- Writes "happy path" tests
- Assumes good faith input
- Optimizes for functionality
BREAKER AGENT:
- Destroys features (in testing)
- Writes "sad path" tests
- Assumes malicious input
- Optimizes for finding failures
RULE: The same agent should NOT build and break.
Use separate sessions or separate agents.
```
---
## ATTACK VECTOR CATEGORIES
### 1. Input Validation Attacks
#### String Attacks
| Attack Type | Test Input | Expected Behavior |
|-------------|------------|-------------------|
| Empty string | `""` | Graceful error, not crash |
| Whitespace only | `" "` | Rejected or trimmed |
| Very long string | 10,000+ characters | Rejected with limit error |
| Unicode edge cases | `"café"`, `"日本語"`, `"🔥🎉"` | Handled correctly |
| Null bytes | `"hello\x00world"` | Sanitized or rejected |
| Newlines | `"line1\nline2"` | Handled per requirements |
| Control characters | `"\t\r\n\b"` | Sanitized |
#### XSS (Cross-Site Scripting) Attacks
```javascript
// Test these inputs against any user-facing text field:
const xssPayloads = [
'',
'
',
'