The only open-source toolkit that red-teams AI agents with REAL tool-call interception.
WHAT IT DOES
Sends 50+ attack prompts against any OpenAI-compatible LLM endpoint OR real agent frameworks (OpenAI Assistants, LangChain, LangServe, CrewAI, custom HTTP). Detects unauthorized tool calls. Generates HTML + PDF + JSON reports with OWASP LLM Top 10 and MITRE ATLAS mapping.
WHAT'S NEW IN v3.0
- Web UI (FastAPI) with live streaming results and PDF export
- Response cache — deterministic re-runs, 30x faster
- Tamper-evident audit log — sha256 hash chain for compliance
- Async concurrency — 10x parallel scans
- Real agent support (OpenAI Assistants API v2, LangServe, custom HTTP)
- Docker multi-stage image (~242 MB)
- Cross-platform: Linux, macOS, WSL, Windows native
ATTACK CATEGORIES
Static:
- Prompt injection
- Jailbreak
- Data leak
- Encoding bypass
- System prompt extraction
Agentic (UNIQUE):
- Confused deputy — tool hijack via fake authority
- Exfiltration chains — multi-tool data theft
- Memory poisoning — persistent rule injection
- Indirect injection — instructions in docs/tool output
- Delegation hijack — sub-agent manipulation
Multiturn:
- Crescendo — gradual escalation
- TAP-lite — adaptive attacker LLM
RAG:
- Document poisoning probes
VERIFIED DEMO
Tested against llama3.1:8b LangChain HTTP agent with send_email + delete_user:
- Static jailbreak: 0 / 30 findings
- Agentic: 10 / 16 findings (all critical)
Promptfoo, Garak, PyRIT do NOT test agentic tool abuse.
WHAT YOU GET
- Full Python source
- Web UI (FastAPI + HTML)
- CLI (redkit)
- Docker image
- 50+ attack prompts, 10 categories
- Real agent support
- HTML + PDF + JSON reports
- OWASP LLM Top 10 + MITRE ATLAS mapping
- Response cache
- Tamper-evident audit log
- Async concurrency scanner
- Plugin system
- Commercial license (unlimited internal use)
REQUIREMENTS
Python 3.10+ OR Docker. Works with Ollama (free), OpenAI, Anthropic, vLLM, LangChain, CrewAI.
SUPPORT
Email. Reply within 48h.
REFUND
7 days, no questions.