Skip to main content

AI Agent Security Competition SDK - Red teaming framework for tool-using AI agents

Project description

JED: Replay-Based Security Benchmark for Tool-Using AI Agents

Python 3.11+ License: MIT PyPI version

JED is a Python SDK and benchmark for evaluating tool-using agents under adversarial pressure.

It supports three package workflows:

  • attack-only evaluation
  • guardrail-only evaluation
  • combined attack+defense evaluation

Documentation: https://mbhatt1.github.io/competitionscratch/

Choose Your Workflow

Use aicomp evaluate when you want the scorer-style public interface and stable machine-readable artifacts. Use aicomp test when you are iterating locally and want run history, compare, and visualize.

Workflow Submission Primary entrypoint Default env Output
Kaggle red-team attack.py aicomp evaluate redteam sandbox normalized attack score
Package attack-only attack.py aicomp test redteam sandbox normalized attack score
Package guardrail-only guardrail.py aicomp test defense sandbox defense score
Package dual-track submission.zip with attack.py and guardrail.py aicomp test dual sandbox attack + defense

The public Kaggle competition uses the attack-only path. The package itself supports all three workflows.

Install

From PyPI:

pip install aicomp-sdk

From source:

git clone https://github.com/mbhatt1/competitionscratch.git
cd competitionscratch
pip install -e .

Quick Start: Attack-Only

Generate a starter submission:

aicomp init attack
aicomp validate redteam attack.py
aicomp test redteam attack.py --budget-s 60 --agent deterministic

Run the standalone public-path scorer locally:

aicomp evaluate \
  redteam \
  attack.py \
  --budget-s 60 \
  --agent deterministic \
  --env gym

attack.py must define AttackAlgorithm, inherit from AttackAlgorithmBase, and return list[AttackCandidate].

If you want CLI behavior that matches the public Kaggle default more closely, use aicomp evaluate redteam attack.py --env gym.

The standalone evaluator defaults to a short terminal summary. Use --verbosity progress for package-owned progress messages. Add --save-transcript, --save-framework-events, and --save-agent-debug when you want transcript.log, framework.jsonl, and agent-debug.jsonl written under --artifacts-dir.

aicomp test keeps its explicit-path diagnostics flags: --transcript-file, --event-log-file, and --agent-debug-jsonl.

Other Supported Package Workflows

Guardrail-only:

aicomp init guardrail
aicomp validate defense guardrail.py
aicomp test defense guardrail.py --budget-s 60 --agent deterministic

Dual-track:

zip submission.zip attack.py guardrail.py
aicomp test dual submission.zip --budget-s 60 --agent deterministic
aicomp evaluate dual submission.zip --budget-s 60 --agent deterministic --env sandbox

How Scoring Works

Attack scoring is replay-based. The evaluator replays each returned AttackCandidate and recomputes:

  • the trace
  • triggered predicates
  • the cell signature
  • the final score

The public Kaggle leaderboard uses normalized attack score only. Package guardrail-only and dual-track workflows also expose defense scoring.

SDK Notes

  • SandboxEnv is the default environment for local evaluator runs.
  • GymAttackEnv is available when you explicitly pass --env gym for Kaggle-style parity.
  • Direct SandboxEnv(...) construction requires an explicit agent= instance.
  • aicomp test defaults to 1800 seconds for redteam, 1800 seconds for defense, and 3600 seconds total for dual (1800/1800 split).

Documentation

Repository Layout

License

MIT. See LICENSE.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

aicomp_sdk-3.1.1.tar.gz (518.4 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

aicomp_sdk-3.1.1-py3-none-any.whl (598.1 kB view details)

Uploaded Python 3

File details

Details for the file aicomp_sdk-3.1.1.tar.gz.

File metadata

  • Download URL: aicomp_sdk-3.1.1.tar.gz
  • Upload date:
  • Size: 518.4 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for aicomp_sdk-3.1.1.tar.gz
Algorithm Hash digest
SHA256 f85628ecb63a0df3edace3e5bdbbb990379a5a804594ffa1726efa7a60d99f15
MD5 ce856c6f76e00c9a977488bb7ad92d42
BLAKE2b-256 1db6cb4fee51af896f101a5745709bb1f4fa77dcfb22f967887a258bfac0c160

See more details on using hashes here.

File details

Details for the file aicomp_sdk-3.1.1-py3-none-any.whl.

File metadata

  • Download URL: aicomp_sdk-3.1.1-py3-none-any.whl
  • Upload date:
  • Size: 598.1 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for aicomp_sdk-3.1.1-py3-none-any.whl
Algorithm Hash digest
SHA256 c6c480ace52e96703429a0afd3a278540ec280c2f2e9176835855aa2b81185fb
MD5 e17178e00deb0492a27ed514ce373584
BLAKE2b-256 c8f121e5839c9146ad23301cf50804a19dc84361c2143f7cf66488ec5f9447af

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page