Red Team Attack Library
The 64 built-in objectives used by Agentic Red Teaming and Model Red Teaming. The library is the same for both.
At a glance
Each objective has an OWASP category, a MITRE ATLAS technique, and a default severity. On top of the library, every run adds:
- Tool-targeted objectives synthesized live for the target after recon (6 in the example runs in Reading Red Team Results).
- Any custom objectives you add, reported under a Custom category.
Quick scan objectives
Full library
LLM07: System Prompt Leakage
LLM01: Prompt Injection
ASI02: Tool Misuse & Exploitation
ASI01: Agent Goal Hijack
The library labels the last two "ASI01: Agent Goal Manipulation" and "ASI01: Agent Goal & Instruction Manipulation"; they map to the same OWASP Agentic ASI01 risk.
ASI03: Identity & Privilege Abuse
LLM05: Improper Output Handling
ASI05: Unexpected Code Execution
LLM02: Sensitive Information Disclosure
ASI06: Memory & Context Poisoning
LLM06: Excessive Agency
LLM10: Unbounded Consumption
LLM08: Vector and Embedding Weaknesses
LLM09: Misinformation
LLM04: Data and Model Poisoning
Coverage notes
- OWASP Top 10 for LLM Applications (2025): LLM01, LLM02, LLM04, LLM05, LLM06, LLM07, LLM08, LLM09, LLM10. No library objective targets LLM03.
- OWASP Top 10 for Agentic Applications: ASI01, ASI02, ASI03, ASI05, ASI06.
- Multimodal and voice objectives (image, audio, document, spoken) target those channels. The report's Capabilities exercised panel shows which channels a run actually exercised; a text-only run reads "text-only target - enable multimodal objectives to exercise vision / audio / document channels".
- A full-library run can complete fewer than 64 library objectives. Check the Objectives run tile on the report for the actual count; the model run in Reading Red Team Results completed 60.