agent-red-teaming
Installation
SKILL.md
Agent Red Teaming
Find exploitable control failures without creating uncontrolled harm. Treat written authorization and rules of engagement as prerequisites for execution, not paperwork to complete afterward.
Inputs
Collect:
- Named target owner and explicit authorization for the exact systems to be tested
- Target identifiers, environment, accounts, endpoints, models, versions, and a reproducible configuration digest
- Start/end time, tester identities, source addresses, rate and cost limits, and emergency contact
- In-scope objectives and out-of-scope systems, tenants, data, techniques, and effects
- Agent architecture, tools, privileges, memory, retrieval, handoffs, identities, and external integrations
- Protected assets, security requirements, prior incidents, existing controls, and expected benign tasks
- Approved synthetic data, canary values, test destinations, cleanup plan, and evidence-handling rules
If target-specific authorization or scope is missing, stop at a non-executable assessment plan. Do not probe a live target to infer scope.