Llm Redteam
llm_redteamProbe AI features for vulnerabilities using garak attack families like indirect-injection and jailbreak. Identify candidate security behaviors for further analysis and reporting.
Instructions
[AGGRESSIVE — requires human approval] Probe the target's AI feature with garak, one probe family at a time.
family: indirect-injection (default), tool-abuse, context-leak, output-handling, or jailbreak. Run llm_probe_catalog first to choose.
Results are candidates. An LLM probe failing is a behaviour, not yet an impact — see the note in the result for what a report needs.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| family | No | indirect-injection | |
| target | Yes | ||
| model_type | No | rest | |
| generations | No |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||