Skip to main content

modelWrecker

An AI red teaming engine. It safely attacks AI systems - LLMs, chatbots, agents, RAG pipelines, and MCP-connected tools - to find security weaknesses before real attackers do, and turns each confirmed weakness into a reproducible finding mapped to standard security taxonomies (OWASP LLM Top 10, OWASP Agentic, OWASP MCP Top 10, MITRE ATLAS).

Status: Phase 4 (minimum engine) in progress. The design, threat model, interfaces, and decisions are complete, and the package is scaffolded (data models, config, interfaces, the security layer, taxonomy, and a CLI skeleton, with a passing offline test suite). The attack loop and concrete adapters are being wired next. See ROADMAP.md.

For authorized testing only. Use modelWrecker on systems you own or have explicit written permission to test.

What makes it different

  • Three clean roles. An attacker that decides what to try, a target that is tested, and a judge that decides if an attack worked - kept strictly separate.
  • Adaptive, not a prompt dump. A planner selects and mutates strategies based on what the target does, instead of firing a fixed list.
  • Findings you can trust. A single success is replayed and scored; only verified, reliable results become findings, each with full reproduction evidence.
  • Secure by design. Auth-by-default, host tools off by default, egress filtering, secret redaction, sandboxed execution - the opposite of a localhost tool with hidden RCE.
  • Free and self-hostable. Runs end-to-end on local models (Ollama / vLLM). Paid model APIs are optional, never required.

Design goals

Modular, low-maintenance, and reusable as the AI red-teaming layer of the Aevrin platform. New strategies, providers, targets, judges, and transforms plug in behind interfaces without touching the core engine.

Where to start reading

License

Apache-2.0 (planned). See docs/decisions/ADR-0002-license.md. modelWrecker does not reuse AGPL-licensed red-team source code; prior tooling informed the design only.

Metadata

Release files for modelwrecker 0.0.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for modelwrecker 0.0.2
File Size Uploaded
modelwrecker-0.0.2.tar.gz 113.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for modelwrecker 0.0.2
File Interpreter ABI Platform
modelwrecker-0.0.2-py3-none-any.whl Python 3 none any Details

Total release size: 225.3 kB

Release files / modelwrecker-0.0.2.tar.gz

Download URL modelwrecker-0.0.2.tar.gz
Size 113.7 kB
Tags Source
SHA-256 checksum
How to use checksums
2f1aa6306c97b33ab32119cf5ace45fd9278635ecda81c28eba40e44edeb6674
BLAKE2b-256 checksum
How to use checksums
3f122c09727a82321c6437e3981a2a7653c016730b3bc141c214392a46d30f4c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / modelwrecker-0.0.2-py3-none-any.whl

Download URL modelwrecker-0.0.2-py3-none-any.whl
Size 111.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
3c969319914f1fb00e26cfdff191a742676f827a83cdcc25f86b5687d9b49833
BLAKE2b-256 checksum
How to use checksums
a0731cb322b12e644d8d2252e329b5a0cc0df2f04a824dd831e58a93cb171816
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release history Release notifications | RSS feed

This release

0.0.2 This release

2 release files

0.0.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page