Skip to main content

modelWrecker

An AI red teaming engine. It safely attacks AI systems - LLMs, chatbots, agents, RAG pipelines, and MCP-connected tools - to find security weaknesses before real attackers do, and turns each confirmed weakness into a reproducible finding mapped to standard security taxonomies (OWASP LLM Top 10, OWASP Agentic, OWASP MCP Top 10, MITRE ATLAS).

Status: Phase 4 (minimum engine) in progress. The design, threat model, interfaces, and decisions are complete, and the package is scaffolded (data models, config, interfaces, the security layer, taxonomy, and a CLI skeleton, with a passing offline test suite). The attack loop and concrete adapters are being wired next. See ROADMAP.md.

For authorized testing only. Use modelWrecker on systems you own or have explicit written permission to test.

What makes it different

  • Three clean roles. An attacker that decides what to try, a target that is tested, and a judge that decides if an attack worked - kept strictly separate.
  • Adaptive, not a prompt dump. A planner selects and mutates strategies based on what the target does, instead of firing a fixed list.
  • Findings you can trust. A single success is replayed and scored; only verified, reliable results become findings, each with full reproduction evidence.
  • Secure by design. Auth-by-default, host tools off by default, egress filtering, secret redaction, sandboxed execution - the opposite of a localhost tool with hidden RCE.
  • Free and self-hostable. Runs end-to-end on local models (Ollama / vLLM). Paid model APIs are optional, never required.

Design goals

Modular, low-maintenance, and reusable as the AI red-teaming layer of the Aevrin platform. New strategies, providers, targets, judges, and transforms plug in behind interfaces without touching the core engine.

Where to start reading

License

Apache-2.0 (planned). See docs/decisions/ADR-0002-license.md. modelWrecker does not reuse AGPL-licensed red-team source code; prior tooling informed the design only.

Metadata

Release files for modelwrecker 0.0.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for modelwrecker 0.0.1
File Size Uploaded
modelwrecker-0.0.1.tar.gz 106.9 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for modelwrecker 0.0.1
File Interpreter ABI Platform
modelwrecker-0.0.1-py3-none-any.whl Python 3 none any Details

Total release size: 214.1 kB

Release files / modelwrecker-0.0.1.tar.gz

Download URL modelwrecker-0.0.1.tar.gz
Size 106.9 kB
Tags Source
SHA-256 checksum
How to use checksums
fb327fea8faf8da8264979b3fbbcb8d64bbfc1518861805afa8930e30705d8fc
BLAKE2b-256 checksum
How to use checksums
866f1cea119955e1699f2cc018a3da14ae96a1f52d68bdcd3183769600d1a327
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / modelwrecker-0.0.1-py3-none-any.whl

Download URL modelwrecker-0.0.1-py3-none-any.whl
Size 107.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
c13dfc73e6f14692ca652f354f5ffb0ff86faab519a57ba59fa5047949264dc3
BLAKE2b-256 checksum
How to use checksums
cf1471a22e83c0b80c9b9456d8f9f9490be82b7b7dd40ed7900fe0a59a1e9512
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release history Release notifications | RSS feed

0.0.2

2 release files

This release

0.0.1 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page