Metadata-Version: 2.5
Name: modelwrecker
Version: 0.0.1
Summary: An AI red teaming engine. Safely attacks AI systems and turns verified weaknesses into reproducible findings.
Project-URL: Homepage, https://app.aevrin.net
Project-URL: Repository, https://github.com/spacesdrive/modelWrecker
Project-URL: Documentation, https://github.com/spacesdrive/modelWrecker/tree/main/docs
Project-URL: Issues, https://github.com/spacesdrive/modelWrecker/issues
Author: Aevrin
License: Apache-2.0
Keywords: ai,jailbreak,llm,owasp,red-teaming,security
Classifier: Development Status :: 3 - Alpha
Classifier: Intended Audience :: Developers
Classifier: Operating System :: OS Independent
Classifier: Programming Language :: Python :: 3
Classifier: Programming Language :: Python :: 3.12
Classifier: Topic :: Security
Requires-Python: >=3.12
Requires-Dist: httpx>=0.27
Requires-Dist: jinja2>=3.1
Requires-Dist: pydantic>=2.7
Requires-Dist: pyyaml>=6.0
Requires-Dist: typer>=0.12
Provides-Extra: all
Requires-Dist: anthropic>=0.34; extra == 'all'
Requires-Dist: any-llm-sdk>=1.25; extra == 'all'
Requires-Dist: detect-secrets>=1.5; extra == 'all'
Requires-Dist: garak>=0.17; extra == 'all'
Requires-Dist: mcp>=2.0; extra == 'all'
Requires-Dist: openai>=1.40; extra == 'all'
Requires-Dist: presidio-analyzer>=2.2; extra == 'all'
Requires-Dist: pyrit>=1.1; extra == 'all'
Provides-Extra: attacks
Requires-Dist: pyrit>=1.1; extra == 'attacks'
Provides-Extra: dev
Requires-Dist: hypothesis>=6.0; extra == 'dev'
Requires-Dist: mypy>=1.11; extra == 'dev'
Requires-Dist: pytest-asyncio>=0.23; extra == 'dev'
Requires-Dist: pytest>=8.0; extra == 'dev'
Requires-Dist: ruff>=0.6; extra == 'dev'
Provides-Extra: judges
Requires-Dist: detect-secrets>=1.5; extra == 'judges'
Requires-Dist: presidio-analyzer>=2.2; extra == 'judges'
Provides-Extra: mcp
Requires-Dist: mcp>=2.0; extra == 'mcp'
Provides-Extra: providers
Requires-Dist: anthropic>=0.34; extra == 'providers'
Requires-Dist: any-llm-sdk>=1.25; extra == 'providers'
Requires-Dist: openai>=1.40; extra == 'providers'
Provides-Extra: scan
Requires-Dist: garak>=0.17; extra == 'scan'
Description-Content-Type: text/markdown

# modelWrecker

**An AI red teaming engine.** It safely attacks AI systems - LLMs, chatbots, agents, RAG
pipelines, and MCP-connected tools - to find security weaknesses before real attackers do, and
turns each confirmed weakness into a **reproducible finding** mapped to standard security
taxonomies (OWASP LLM Top 10, OWASP Agentic, OWASP MCP Top 10, MITRE ATLAS).

> **Status: Phase 4 (minimum engine) in progress.** The design, threat model, interfaces, and decisions
> are complete, and the package is scaffolded (data models, config, interfaces, the security layer,
> taxonomy, and a CLI skeleton, with a passing offline test suite). The attack loop and concrete
> adapters are being wired next. See [`ROADMAP.md`](ROADMAP.md).

> **For authorized testing only.** Use modelWrecker on systems you own or have explicit written
> permission to test.

## What makes it different

- **Three clean roles.** An **attacker** that decides what to try, a **target** that is tested,
  and a **judge** that decides if an attack worked - kept strictly separate.
- **Adaptive, not a prompt dump.** A planner selects and mutates strategies based on what the
  target does, instead of firing a fixed list.
- **Findings you can trust.** A single success is replayed and scored; only verified, reliable
  results become findings, each with full reproduction evidence.
- **Secure by design.** Auth-by-default, host tools off by default, egress filtering, secret
  redaction, sandboxed execution - the opposite of a localhost tool with hidden RCE.
- **Free and self-hostable.** Runs end-to-end on local models (Ollama / vLLM). Paid model APIs
  are optional, never required.

## Design goals

Modular, low-maintenance, and reusable as the AI red-teaming layer of the Aevrin platform. New
strategies, providers, targets, judges, and transforms plug in behind interfaces without touching
the core engine.

## Where to start reading

- [`CLAUDE.md`](CLAUDE.md) - the project rules and reading order.
- [`docs/index.md`](docs/index.md) - the full documentation map.
- [`docs/architecture/OVERVIEW.md`](docs/architecture/OVERVIEW.md) - how the whole thing fits together.
- [`docs/security/SECURITY.md`](docs/security/SECURITY.md) - the security model.

## License

Apache-2.0 (planned). See [`docs/decisions/ADR-0002-license.md`](docs/decisions/ADR-0002-license.md).
modelWrecker does **not** reuse AGPL-licensed red-team source code; prior tooling informed the design only.