Rank
65
LangChain/LangGraph tools for AI agent x402 payments on X1
Traction
No public download signal
Freshness
Updated 4mo ago
Xpersona Agent
Open-source security testing for LLM-based agents. 7 attack classes (5 novel beyond OWASP/ATLAS), 19 scenarios, LangChain + CrewAI support, LLM-as-judge defense layer. **⚠️ ARCHIVED** — This project is archived. The 7 attack classes and LLM-as-judge defense findings remain valid, but no further development is planned. Agent security research continues in $1 and $1. Agent Security Red-Team Framework Reasoning chain hijacking hits 100% success against default LangChain ReAct agents. 7 attack classes systematized — 5 absent from OWASP LLM Top 10 and MITRE ATLAS. Layered defense reduce
git clone https://github.com/rexcoleman/agent-redteam-framework.gitOverall rank
#20
Adoption
No public adoption signal
Trust
Unknown
Freshness
Jun 1, 2026
Freshness
Last checked Jun 1, 2026
Best For
agent-redteam-framework is best for crewai, multi-agent workflows where OpenClaw compatibility matters.
Not Ideal For
Contract metadata is missing or unavailable for deterministic execution.
Evidence Sources Checked
editorial-content, GITHUB OPENCLEW, runtime-metrics, public facts pack
Key links, install path, reliability highlights, and the shortest practical read before diving into the crawl record.
Overview
Open-source security testing for LLM-based agents. 7 attack classes (5 novel beyond OWASP/ATLAS), 19 scenarios, LangChain + CrewAI support, LLM-as-judge defense layer. **⚠️ ARCHIVED** — This project is archived. The 7 attack classes and LLM-as-judge defense findings remain valid, but no further development is planned. Agent security research continues in $1 and $1. Agent Security Red-Team Framework Reasoning chain hijacking hits 100% success against default LangChain ReAct agents. 7 attack classes systematized — 5 absent from OWASP LLM Top 10 and MITRE ATLAS. Layered defense reduce Capability contract not published. No trust telemetry is available yet. Last updated 6/1/2026.
Trust score
Unknown
Compatibility
OpenClaw
Freshness
Jun 1, 2026
Vendor
Rexcoleman
Artifacts
0
Benchmarks
0
Last release
Unpublished
Install & run
git clone https://github.com/rexcoleman/agent-redteam-framework.gitSetup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.
Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Public facts grouped by evidence type, plus release and crawl events with provenance and freshness.
Public facts
Vendor
Rexcoleman
Protocol compatibility
OpenClaw
Handshake status
UNKNOWN
Events
Parameters, dependencies, examples, extracted files, editorial overview, and the complete README when available.
Captured outputs
Extracted files
0
Examples
2
Snippets
0
Languages
python
bash
# Clone and install git clone https://github.com/rexcoleman/agent-redteam-framework.git cd agent-redteam-framework conda env create -f environment.yml conda activate agent-redteam pip install -e . # Set your API key export ANTHROPIC_API_KEY="sk-ant-api03-..." # Verify environment agent-redteam verify-env # Run attacks against LangChain ReAct agent agent-redteam scan --agent langchain_react --attack all --seed 42 # Evaluate defenses agent-redteam defend --agent langchain_react --defense layered --seed 42 # Generate figures agent-redteam figures
text
src/ agents/ # Agent target abstractions (LangChain, CrewAI) attacks/ # Attack class implementations defenses/ # Defense layers (input sanitizer, tool boundary, layered) core/ # Config, types, logging cli.py # CLI entry point scripts/ # Experiment runners + govML-generated scripts config/ # YAML configuration (agents, attacks, defenses) data/tasks/ # YAML-driven attack scenarios docs/ # govML governance documents (22 templates) blog/ # Blog draft + conference abstract + images
Editorial read
Docs source
GITHUB OPENCLEW
Editorial quality
ready
Open-source security testing for LLM-based agents. 7 attack classes (5 novel beyond OWASP/ATLAS), 19 scenarios, LangChain + CrewAI support, LLM-as-judge defense layer. **⚠️ ARCHIVED** — This project is archived. The 7 attack classes and LLM-as-judge defense findings remain valid, but no further development is planned. Agent security research continues in $1 and $1. Agent Security Red-Team Framework Reasoning chain hijacking hits 100% success against default LangChain ReAct agents. 7 attack classes systematized — 5 absent from OWASP LLM Top 10 and MITRE ATLAS. Layered defense reduce
⚠️ ARCHIVED — This project is archived. The 7 attack classes and LLM-as-judge defense findings remain valid, but no further development is planned. Agent security research continues in multi-agent-security and agent-semantic-resistance.
Reasoning chain hijacking hits 100% success against default LangChain ReAct agents. 7 attack classes systematized — 5 absent from OWASP LLM Top 10 and MITRE ATLAS. Layered defense reduces overall success by 60%.
Blog post: I Red-Teamed AI Agents: Here's How They Break


# Clone and install
git clone https://github.com/rexcoleman/agent-redteam-framework.git
cd agent-redteam-framework
conda env create -f environment.yml
conda activate agent-redteam
pip install -e .
# Set your API key
export ANTHROPIC_API_KEY="sk-ant-api03-..."
# Verify environment
agent-redteam verify-env
# Run attacks against LangChain ReAct agent
agent-redteam scan --agent langchain_react --attack all --seed 42
# Evaluate defenses
agent-redteam defend --agent langchain_react --defense layered --seed 42
# Generate figures
agent-redteam figures
| Class | Success Rate | Status | |-------|-------------|--------| | Direct Prompt Injection | 80% | Known (OWASP LLM01) | | Indirect Injection via Tools | 25% | Partially known | | Tool Permission Boundary Violation | 75% | Systematized | | Memory/Context Poisoning | 67% | Systematized | | Reasoning Chain Hijacking | 100% | Novel pattern |
See docs/attack_taxonomy.md for the full taxonomy and FINDINGS.md for detailed results.
src/
agents/ # Agent target abstractions (LangChain, CrewAI)
attacks/ # Attack class implementations
defenses/ # Defense layers (input sanitizer, tool boundary, layered)
core/ # Config, types, logging
cli.py # CLI entry point
scripts/ # Experiment runners + govML-generated scripts
config/ # YAML configuration (agents, attacks, defenses)
data/tasks/ # YAML-driven attack scenarios
docs/ # govML governance documents (22 templates)
blog/ # Blog draft + conference abstract + images
Built with govML v2.4 (security-ml profile, 22 templates). Key governance documents:
docs/PROJECT_BRIEF.md — Thesis, research questions, success criteriadocs/DECISION_LOG.md — 3 architecture decision recordsdocs/ADVERSARIAL_EVALUATION.md — Threat model + controllability matrixdocs/PUBLICATION_PIPELINE.md — Blog distribution governanceMIT
Machine endpoints, contract coverage, trust signals, runtime metrics, benchmarks, and guardrails for agent-to-agent use.
Machine interfaces
Contract coverage
Status
missing
Auth
None
Streaming
No
Data region
Unspecified
Protocol support
Requires: none
Forbidden: none
Guardrails
Operational confidence: low
curl -s "https://www.xpersona.co/api/v1/agents/crewai-rexcoleman-agent-redteam-framework/snapshot"
curl -s "https://www.xpersona.co/api/v1/agents/crewai-rexcoleman-agent-redteam-framework/contract"
curl -s "https://www.xpersona.co/api/v1/agents/crewai-rexcoleman-agent-redteam-framework/trust"
Operational fit
Trust signals
Handshake
UNKNOWN
Confidence
unknown
Attempts 30d
unknown
Fallback rate
unknown
Runtime metrics
Observed P50
unknown
Observed P95
unknown
Rate limit
unknown
Estimated cost
unknown
Do not use if
Raw contract, invocation, trust, capability, facts, and change-event payloads for machine-side inspection.
Contract JSON
{
"contractStatus": "missing",
"authModes": [],
"requires": [],
"forbidden": [],
"supportsMcp": false,
"supportsA2a": false,
"supportsStreaming": false,
"inputSchemaRef": null,
"outputSchemaRef": null,
"dataRegion": null,
"contractUpdatedAt": null,
"sourceUpdatedAt": null,
"freshnessSeconds": null
}Invocation Guide
{
"preferredApi": {
"snapshotUrl": "https://www.xpersona.co/api/v1/agents/crewai-rexcoleman-agent-redteam-framework/snapshot",
"contractUrl": "https://www.xpersona.co/api/v1/agents/crewai-rexcoleman-agent-redteam-framework/contract",
"trustUrl": "https://www.xpersona.co/api/v1/agents/crewai-rexcoleman-agent-redteam-framework/trust"
},
"curlExamples": [
"curl -s \"https://www.xpersona.co/api/v1/agents/crewai-rexcoleman-agent-redteam-framework/snapshot\"",
"curl -s \"https://www.xpersona.co/api/v1/agents/crewai-rexcoleman-agent-redteam-framework/contract\"",
"curl -s \"https://www.xpersona.co/api/v1/agents/crewai-rexcoleman-agent-redteam-framework/trust\""
],
"jsonRequestTemplate": {
"query": "summarize this repo",
"constraints": {
"maxLatencyMs": 2000,
"protocolPreference": [
"OPENCLEW"
]
}
},
"jsonResponseTemplate": {
"ok": true,
"result": {
"summary": "...",
"confidence": 0.9
},
"meta": {
"source": "GITHUB_OPENCLEW",
"generatedAt": "2026-10-08T22:18:42.767Z"
}
},
"retryPolicy": {
"maxAttempts": 3,
"backoffMs": [
500,
1500,
3500
],
"retryableConditions": [
"HTTP_429",
"HTTP_503",
"NETWORK_TIMEOUT"
]
}
}Trust JSON
{
"status": "unavailable",
"handshakeStatus": "UNKNOWN",
"verificationFreshnessHours": null,
"reputationScore": null,
"p95LatencyMs": null,
"successRate30d": null,
"fallbackRate": null,
"attempts30d": null,
"trustUpdatedAt": null,
"trustConfidence": "unknown",
"sourceUpdatedAt": null,
"freshnessSeconds": null
}Capability Matrix
{
"rows": [
{
"key": "OPENCLEW",
"type": "protocol",
"support": "unknown",
"confidenceSource": "profile",
"notes": "Listed on profile"
},
{
"key": "crewai",
"type": "capability",
"support": "supported",
"confidenceSource": "profile",
"notes": "Declared in agent profile metadata"
},
{
"key": "multi-agent",
"type": "capability",
"support": "supported",
"confidenceSource": "profile",
"notes": "Declared in agent profile metadata"
}
],
"flattenedTokens": "protocol:OPENCLEW|unknown|profile capability:crewai|supported|profile capability:multi-agent|supported|profile"
}Facts JSON
[
{
"factKey": "vendor",
"label": "Vendor",
"value": "Rexcoleman",
"category": "vendor",
"href": "https://github.com/rexcoleman/agent-redteam-framework",
"sourceUrl": "https://github.com/rexcoleman/agent-redteam-framework",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-05-24T06:16:46.611Z",
"isPublic": true,
"metadata": {}
},
{
"factKey": "protocols",
"label": "Protocol compatibility",
"value": "OpenClaw",
"category": "compatibility",
"href": "https://www.xpersona.co/api/v1/agents/crewai-rexcoleman-agent-redteam-framework/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/crewai-rexcoleman-agent-redteam-framework/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-05-24T06:16:46.611Z",
"isPublic": true,
"metadata": {}
},
{
"factKey": "handshake_status",
"label": "Handshake status",
"value": "UNKNOWN",
"category": "security",
"href": "https://www.xpersona.co/api/v1/agents/crewai-rexcoleman-agent-redteam-framework/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/crewai-rexcoleman-agent-redteam-framework/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true,
"metadata": {}
}
]Change Events JSON
[]
Sponsored
Ads related to agent-redteam-framework and adjacent AI workflows.