Aegis Red
Authorized assurance harness for AI applications and agents. Site: aeigisred.ai. Free install: pip install aegis-red.
Domain industries live under catalog/domains/: safety (Tech / AI), banking, insurance, and security. Each industry has auditor folders for OSS, NIST, ISO, OWASP, and the EU AI Act. The free version is a nudge catalog only. The complete pack lives in catalog/commercial/ (enable the pack in aegis.yaml after install). Community seeds live in catalog/contrib/seed_store.
Aegis is a platform, not an unsupervised attacker. Seeds are intents, fixtures, and oracles — not exploit recipes. Copyright rfintek Inc. The catalog is YAML, not a database.
The problem
Agents can leak secrets, invent facts, honor a fake policy, or call tools they were never granted. Teams need Pass/Fail evidence without publishing a jailbreak cookbook.
Try it (few clicks)
You do not need a bank agent. The portal can mock-test against an in-process twin, or hit a live HTTP demo SUT.
The GitHub project is private. Install the signed wheel from PyPI — not a source zip, not a public clone.
macOS
python3 -m venv .venv
source .venv/bin/activate
python -m pip install -U pip
pip install aegis-red
aegis-red try
Windows
py -3 -m venv .venv
.venv\Scripts\Activate.ps1
python -m pip install -U pip
pip install aegis-red
aegis-red try
Then open http://127.0.0.1:8080 (product site), http://127.0.0.1:8080/docs, and http://127.0.0.1:8080/app (tester). The public Start now form captures a short lead and shows the same commands.
| Audience | What to do in the portal |
|---|---|
| UAT / QA | Try now → add 1–2 tests in plain language → Run this test → download Pass/Fail CSV |
| Tester | Add tests — portal form or YAML on this machine; request complete coverage when the nudge is not enough |
| Engineer | Get started, then on Try now pick one SUT (twin, live HTTP, or OpenAI) |
Already installed:
pip install -U aegis-red
aegis-red doctor
aegis-red try # product site + tester + live demo SUT, opens the browser
aegis-red try starts the site on port 8080 and a live demo agent on port 8090. Verify a wheel with python -m sigstore verify github --repository aegis-red/aegis-red path/to/aegis_red-*.whl. Licensed source checkout (if rfintek granted access) still uses pip install -e ".[dev]". Serve the customer site on the internet with aegis-red serve --host 0.0.0.0 behind TLS (docs/PUBLISH.md).
How we test AI
| Area | What a seed proves |
|---|---|
| Content safety | Harmful asks are refused |
| Prompt injection / instruction integrity | Official policy stays bound |
| Hallucination / grounding | Unpublished facts are not invented |
| Cross-tenant privacy | Other tenants' secrets stay closed |
| Tool contract | Denied tools stay denied |
| Policy robustness | A claimed policy rewrite does not grant tools or wires |
| Memory ≠ policy | Memory is not authorization |
| Swarm isolation | Peers cannot tailgate privilege |
| Evidence / lineage | Hashed bundles: harness sent vs agent reply |
Banking pack (optional): KYC, cards, wires, legal, compliance, risk, marketing, audit.
This is not Garak/Promptfoo/PyRIT: those probe models with attack corpora. Aegis scores an authorized agent against oracles and hashed evidence. Seeds describe intent; they are not an exploit cookbook.
Live SUT
aegis.yaml lists named profiles. One is active at a time. Pick it with sut.active, AEGIS_SUT, or aegis-red run --sut <profile>.
# aegis.yaml
sut:
active: twin
profiles:
twin:
kind: twin
http:
kind: http
base_url: http://127.0.0.1:8090
openai:
kind: openai
model: gpt-4o-mini
api_base: https://api.openai.com/v1
api_key_env: OPENAI_API_KEY
AEGIS_SUT=twin aegis-red run core_safety
AEGIS_SUT=http aegis-red run core_safety # needs `aegis-red demo-sut` or `aegis-red try`
AEGIS_SUT=openai aegis-red run core_safety # needs OPENAI_API_KEY in the environment
aegis-red run core_safety --sut openai
Do not commit API keys. Put OPENAI_API_KEY in .env (see .env.example). Do not point the HTTP demo adapter at a public model API; use kind: openai for OpenAI.
Weak string oracles (invented APR, unpublished facts, secrets, RAG grounding) fill a reply_claims_v1 JSON schema from the reply, then Python compares those claims to the twin. Default extractor.mode is local (same schema, no network). Set AEGIS_EXTRACTOR=llm to have a model fill the schema at temperature 0. The model does not decide Pass/Fail. Unclear extract is inconclusive, not hold.
Or leave the active profile as twin and pick OpenAI / live HTTP in the portal. aegis-red try starts the HTTP demo agent on port 8090.
Your own agent: register aegis_red.sut and implement handle(seed, persona, utterance) -> Turn. See CONTRIBUTING.md.
Packs (aegis.yaml)
The free version is a nudge catalog across domain industries: safety, banking, insurance, and security. Each industry has auditor folders (oss, nist, iso, owasp, ai_act). Community seeds stay in catalog/contrib/seed_store. The complete pack is the commercial package (catalog/commercial/seeds/<industry>/) and is not loaded unless you add that pack to aegis.yaml. Generate it with python -m aegis_red.commercial_seeds.
packs:
- id: safety
path: catalog/domains/safety
- id: banking
path: catalog/domains/banking
- id: insurance
path: catalog/domains/insurance
- id: security
path: catalog/domains/security
- id: seed_store
path: catalog/contrib/seed_store
# Complete pack (not the free nudge):
# - id: commercial
# path: catalog/commercial
aegis-red extensions
aegis-red run core_safety --sut twin
aegis-red run owasp_llm_2026 --sut twin
aegis-red run osaid_1_0 --sut twin
aegis-red run nist_ai_600_1 --sut twin
aegis-red run iso_42001 --sut twin
aegis-red run eu_ai_act --sut twin
aegis-red run seed_store
aegis-red serve # portal only (twin)
aegis-red serve --live-sut # portal + live agent
go exits 0. no-go (critical breach) exits 2.
Add tests
This product is proprietary. The tester portal tab is Add tests, not a public contribution board.
- Add a test on Try now (plain language)
- Save YAML under
catalog/domains/<industry>/seeds/user/ - Point the harness at your agent
- Request complete coverage from the public site when the nudge is not enough
Licensed source work (if rfintek granted you repo access) is described in CONTRIBUTING.md. Read CODE_OF_CONDUCT.md, SECURITY.md, and docs/PUBLISH.md. Do not publish exploit recipes.
Tests
pytest
Metadata
Release files for aegis-red 0.2.3
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| aegis_red-0.2.3-py3-none-any.whl | Python 3 | none | any | Details |
Release files / aegis_red-0.2.3-py3-none-any.whl
| Download URL | aegis_red-0.2.3-py3-none-any.whl |
|---|---|
| Size | 292.0 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
ffe974a4f02dcca94a8911240901b8d9ecf8bf76a5efa3ad438008a6130624e6
|
|
BLAKE2b-256 checksum How to use checksums |
6d985c0498b6741a3dd98456fa51a093e0ac74aba010a83ce356acc6fba9ea65
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 7, 2026.
Transparency log