Weapons-grade automated red teaming and bug bounty toolchain for LLMs and autonomous agents. Native Go speed, multi-stage exploit chaining, and instant triager-ready reports.
Field-manual attack workflows covering prompt injection, delimiter smuggling, indirect poisoning, tool parameter abuse, and state exfiltration.
Comprehensive Agent Threat Rules (ATR) covering privilege escalation, authorization bypasses, and unauthorized tool execution boundaries.
Direct sync with HackerOne and Bugcrowd feeds. Real-time scope verification blocks unauthorized queries before packets leave your machine.
Export full playbooks and assertions to production promptfooconfig.yaml suites with a single CLI command.
Zero-Python native binaries running directly on Windows, Linux, and macOS.