Skip to main content

Red Teaming overview

Red Teaming actively tests your LLM apps, MCP servers, agents, and models for weaknesses before attackers find them. It lives in the console under Assessments.

Go toQuilrAI consoleAssessmentsRed Teaming

The four tools​

The Red Teaming page has one tab per tool.

TabTargetWhat it testsOutput
LLM Intelligence AssessmentThe model behind an LLM Gateway app (provider, model, system prompt, tools)A fixed corpus of adversarial and benchmark suites (Prompt Attacks, Grounded Answering, Hallucination, and more)Pass rate per suite, Guardian counterfactual, framework rollups, knowledge horizon
MCP Threat DetectionAn MCP server: a public repository and/or a live serverStatic and dependency (CVE) scan, read-only tool-surface enumeration, threat modelA scan with findings and coverage
Agentic Red TeamingA live agent over HTTP, WebSocket, or voiceAdaptive, multi-turn attacks, including tool abuseLetter grade, risk score, findings, remediation
Model Red TeamingOne model, or 2 to 8 models side by sideThe same adaptive engine as Agentic Red Teaming, pointed at the model directlyLetter grade, risk score, findings; a campaign view when comparing

Model behind an app vs. the live app​

The two most common choices test different things:

LLM Intelligence AssessmentAgentic Red Teaming
What is attackedThe model configured on an LLM Gateway appYour deployed agent or app at its own HTTP, WebSocket, or voice endpoint
How it is calledDirectly at the provider, with the app's provider credentials, system prompt and tool definitionsThrough the same endpoint your users call, so whatever sits in that path (including the gateway, if the app uses it) is tested
Gateway guardrails in the pathNo. The run measures the raw model, so you can see how much protection the gateway needs to add.Yes, if your app sends its traffic through the gateway
Use it toBenchmark or compare models behind a gateway appTest the live app or agent end to end before launch

Which one to use​

  • Choosing or changing the model behind a gateway app, or measuring how much protection the gateway adds: LLM Intelligence Assessment. The corpus is fixed, so runs before and after a change are comparable.
  • Before you approve or install an MCP server: MCP Threat Detection.
  • Before you ship an agent, or after changing its prompt or tools: Agentic Red Teaming.
  • Comparing candidate models on the same attacks: Model Red Teaming.

Shared concepts​

ConceptWhat it is
RunOne execution of an assessment against one target. LLM Intelligence Assessment lists them under Recent runs and Results; Agentic and Model Red Teaming under Runs; MCP Threat Detection under Recent scans.
FindingA confirmed weakness with severity, framework mapping (OWASP, MITRE ATLAS, NIST AI RMF), evidence, and a recommended fix.
Findings trackerAgentic and Model Red Teaming share a Findings sub-tab where you assign, track, and close findings. See Runs, findings and schedules.
ScheduleRe-runs the same authorized Agentic or Model assessment on a cadence, from the Schedules sub-tab.
ReportThe result of a run. See Reading a report.

Agentic and Model Red Teaming share the same sub-tabs (New assessment, Runs, Findings, Schedules) and the same Attack library of 64 objectives.

Prerequisites​

ToolYou need
LLM Intelligence AssessmentAn LLM Gateway app with a configured provider and model, and an active Quilr key. The form warns when the app has none. See Applications and keys.
MCP Threat DetectionA public repository URL and/or a reachable MCP server.
Agentic Red TeamingAn agent endpoint you are authorized to test (HTTP endpoint, WebSocket endpoint, or voice agent).
Model Red TeamingA model source. Models connected in Settings › Models appear as Your models; see Providers and models.
warning

Only test targets you own or are authorized to test. Agentic Red Teaming, Model Red Teaming, and MCP Threat Detection require an acknowledgement before a run starts.

Next steps​