SuperRed

C
C tier on AI Security Testing ToolsScore 6.3 · #11 of 29
Android app
Not listed
Free plan
No
Runs on
Linux

Summary

SuperRed is ranked #11 of 29 in AI security testing tools on Everything Xiaomi. It runs on Linux.

Compared on AI security testing tools

Free plan
Yesrdi.berkeley.edu
Prompt injection tests
Yesrdi.berkeley.edu
Jailbreak tests
Yesrdi.berkeley.edu
Data leakage tests
Yesrdi.berkeley.edu
Unsafe output tests
Yesrdi.berkeley.edu
Custom test cases
Yesrdi.berkeley.edu
Deployment mode
self_hostedrdi.berkeley.edu

Facts

Purpose
SuperRed is an open-source framework for red-teaming chatbots, agents, and assistants by testing whether attacks can violate security properties.rdi.berkeley.edu · 4 Oct 2026
Composable components
It treats the attacker, system under test, and benchmark as separate interchangeable modules coordinated by a controller.rdi.berkeley.edu · 4 Oct 2026
Threat models
Each run can define attacker model, per-task budget, trust-boundary access, and whether benchmark feedback is visible to the attacker.rdi.berkeley.edu · 4 Oct 2026
Attacks and benchmarks
The module catalogue lists 35 modules: 21 attackers, 6 targets, and 8 benchmarks.rdi.berkeley.edu · 4 Oct 2026
Example modules
Listed modules include PAIR, TAP, AutoDAN-Turbo, Crescendo, AgentVigil, HarmBench, AgentDojo, and DecodingTrust-Agent.rdi.berkeley.edu · 4 Oct 2026
Metrics and reports
Runs record model, cost, and success rate, with a live terminal dashboard and a web report for results.rdi.berkeley.edu · 4 Oct 2026
Parallel runs
The framework can run multiple threat models in parallel, each against its own system instance.rdi.berkeley.edu · 4 Oct 2026
Installation
The guide installs the framework with pip install superred and describes it as a Python framework whose guide assumes familiarity with Python and asyncio.rdi.berkeley.edu · 4 Oct 2026
Model endpoints
The example target uses a LiteLLM-compatible endpoint with a base URL and API key; the guide says most LLM-driven attackers also call models through LiteLLM.rdi.berkeley.edu · 4 Oct 2026
Target types
Targets can wrap fixed-response fixtures, simulated environments, sandboxes, or live deployments.rdi.berkeley.edu · 4 Oct 2026
Security scope
The controller filters which controllables, observables, trajectory entries, and evaluation sub-scores the optimizer can access according to the configured scope.rdi.berkeley.edu · 4 Oct 2026
Sensitive results
Persisted trajectories are not scrubbed and may contain jailbreaks, planted secrets, and exfiltrated content; API keys and API base URLs are not written in the serialized LLM configuration.rdi.berkeley.edu · 4 Oct 2026
Intended users
The project describes use by red-teamers, system builders, and evaluators, and its guide covers wrapping systems, writing attackers, defining success criteria, and running evaluations.rdi.berkeley.edu · 4 Oct 2026
Maker
The site says SuperRed was made at the University of California, Berkeley.rdi.berkeley.edu · 4 Oct 2026
Composable modules
It keeps attackers, systems under test, and security claims as interchangeable modules coordinated by a controller.rdi.berkeley.edu · 4 Oct 2026
Evaluation reports
Runs record model, cost, and success rate; the framework provides live progress and browsable reports with per-task details and trajectories.rdi.berkeley.edu · 4 Oct 2026
Scale
The controller can run many threat models in parallel, each against its own system instance.rdi.berkeley.edu · 4 Oct 2026
Supported targets
Targets can wrap fixed-response fixtures, simulated environments, sandboxes, or live deployments, and the guide recommends staging or throwaway instances for real systems.rdi.berkeley.edu · 4 Oct 2026
Integration
The getting-started example connects to any LiteLLM-compatible model endpoint using a base URL and API key.rdi.berkeley.edu · 4 Oct 2026
Security controls
The controller filters attacker-visible and injectable surfaces according to security-domain scopes and can cap attacker model spend per task.rdi.berkeley.edu · 4 Oct 2026
Requirements
The package requires Python 3.11 through 3.13; Python 3.14 is not supported.pypi.org · 4 Oct 2026
License and maturity
PyPI lists the package under the MIT license and classifies its development status as Alpha.pypi.org · 4 Oct 2026
Intended audience
The getting-started guide is for people who can read Python and have seen asyncio, and PyPI lists Science/Research as an intended audience.rdi.berkeley.edu · 4 Oct 2026

Best SuperRed alternatives

See all 12

Where it ranks on Everything Xiaomi

Is SuperRed yours?

Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.

Sources