{"id":"aff6a87b-17a9-47ff-8446-085cebf1f0de","entityType":"agent","slug":"crewai-rexcoleman-agent-redteam-framework","name":"agent-redteam-framework","canonicalUrl":"https://www.xpersona.co/agent/crewai-rexcoleman-agent-redteam-framework","canonicalPath":"/agent/crewai-rexcoleman-agent-redteam-framework","generatedAt":"2026-10-09T01:01:01.414Z","source":"GITHUB_OPENCLEW","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-05-18T06:45:33.847Z","emptyReason":null},"description":"Open-source security testing for LLM-based agents. 7 attack classes (5 novel beyond OWASP/ATLAS), 19 scenarios, LangChain + CrewAI support, LLM-as-judge defense layer. **⚠️ ARCHIVED** — This project is archived. The 7 attack classes and LLM-as-judge defense findings remain valid, but no further development is planned. Agent security research continues in $1 and $1. Agent Security Red-Team Framework Reasoning chain hijacking hits 100% success against default LangChain ReAct agents. 7 attack classes systematized — 5 absent from OWASP LLM Top 10 and MITRE ATLAS. Layered defense reduce","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. Last updated 5/18/2026.","installCommand":"git clone https://github.com/rexcoleman/agent-redteam-framework.git","sourceUrl":"https://github.com/rexcoleman/agent-redteam-framework","homepage":null,"primaryLinks":[{"label":"View Source","url":"https://github.com/rexcoleman/agent-redteam-framework","kind":"source"}],"safetyScore":66,"overallRank":20.8,"popularityScore":0,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Open-source security testing for LLM-based agents. 7 attack classes (5 novel beyond OWASP/ATLAS), 19 scenarios, LangChain + CrewAI support, LLM-as-judge defense"},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-05-18T06:45:33.847Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[{"label":"crewai","status":"self-declared"},{"label":"multi-agent","status":"self-declared"}],"verifiedCount":0,"selfDeclaredCount":3,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"},{"key":"crewai","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"},{"key":"multi-agent","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile capability:crewai|supported|profile capability:multi-agent|supported|profile"}},"adoption":{"evidence":{"source":"no-adoption-signals","verified":false,"confidence":"low","updatedAt":"2026-05-18T06:45:33.847Z","emptyReason":"No source adoption metrics were available."},"stars":0,"forks":0,"downloads":null,"packageName":null,"latestVersion":null,"tractionLabel":null},"release":{"evidence":{"source":"agent-index","verified":false,"confidence":"medium","updatedAt":"2026-05-18T06:45:33.847Z","emptyReason":null},"lastUpdatedAt":"2026-05-18T06:45:33.847Z","lastCrawledAt":"2026-05-18T06:45:33.847Z","lastIndexedAt":null,"nextCrawlAt":"2026-05-25T06:45:33.847Z","lastVerifiedAt":null,"highlights":[]},"execution":{"evidence":{"source":"GITHUB OPENCLEW","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"git clone https://github.com/rexcoleman/agent-redteam-framework.git","setupComplexity":"low","setupSteps":["Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/crewai-rexcoleman-agent-redteam-framework/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/crewai-rexcoleman-agent-redteam-framework/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/crewai-rexcoleman-agent-redteam-framework/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/crewai-rexcoleman-agent-redteam-framework/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/crewai-rexcoleman-agent-redteam-framework/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/crewai-rexcoleman-agent-redteam-framework/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"GITHUB_OPENCLEW","generatedAt":"2026-10-09T01:01:01.414Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/crewai-rexcoleman-agent-redteam-framework/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/crewai-rexcoleman-agent-redteam-framework/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/crewai-rexcoleman-agent-redteam-framework/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/crewai-rexcoleman-agent-redteam-framework/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"GITHUB OPENCLEW","verified":false,"confidence":"high","updatedAt":"2026-05-18T06:45:33.847Z","emptyReason":null},"readme":"> **⚠️ ARCHIVED** — This project is archived. The 7 attack classes and LLM-as-judge defense findings remain valid, but no further development is planned. Agent security research continues in [multi-agent-security](https://github.com/rexcoleman/multi-agent-security) and [agent-semantic-resistance](https://github.com/rexcoleman/agent-semantic-resistance).\n\n# Agent Security Red-Team Framework\n\nReasoning chain hijacking hits 100% success against default LangChain ReAct agents. 7 attack classes systematized — 5 absent from OWASP LLM Top 10 and MITRE ATLAS. Layered defense reduces overall success by 60%.\n\n**Blog post:** [I Red-Teamed AI Agents: Here's How They Break](https://rexcoleman.dev/posts/agent-redteam/)\n\n## Key Findings\n\n- **7 attack classes** systematized into a reusable taxonomy (5 not covered by OWASP LLM Top 10 / MITRE ATLAS)\n- **Reasoning chain hijacking**: 100% success rate against default-configured LangChain ReAct agents (Claude Sonnet, 3 seeds) — the most dangerous agent-specific attack pattern tested\n- **Layered defense** reduces overall attack success by 60%\n- **Adversarial control analysis** validated across 3 domains (IDS, CVE prediction, agents)\n\n![Attack Success Rates](blog/images/attack_success_rates.png)\n\n![Defense Comparison](blog/images/defense_comparison.png)\n\n## Quick Start\n\n```bash\n# Clone and install\ngit clone https://github.com/rexcoleman/agent-redteam-framework.git\ncd agent-redteam-framework\nconda env create -f environment.yml\nconda activate agent-redteam\npip install -e .\n\n# Set your API key\nexport ANTHROPIC_API_KEY=\"sk-ant-api03-...\"\n\n# Verify environment\nagent-redteam verify-env\n\n# Run attacks against LangChain ReAct agent\nagent-redteam scan --agent langchain_react --attack all --seed 42\n\n# Evaluate defenses\nagent-redteam defend --agent langchain_react --defense layered --seed 42\n\n# Generate figures\nagent-redteam figures\n```\n\n## Attack Taxonomy\n\n| Class | Success Rate | Status |\n|-------|-------------|--------|\n| Direct Prompt Injection | 80% | Known (OWASP LLM01) |\n| Indirect Injection via Tools | 25% | Partially known |\n| **Tool Permission Boundary Violation** | **75%** | **Systematized** |\n| **Memory/Context Poisoning** | **67%** | **Systematized** |\n| **Reasoning Chain Hijacking** | **100%** | **Novel pattern** |\n\nSee [`docs/attack_taxonomy.md`](docs/attack_taxonomy.md) for the full taxonomy and [`FINDINGS.md`](FINDINGS.md) for detailed results.\n\n## Architecture\n\n```\nsrc/\n  agents/           # Agent target abstractions (LangChain, CrewAI)\n  attacks/          # Attack class implementations\n  defenses/         # Defense layers (input sanitizer, tool boundary, layered)\n  core/             # Config, types, logging\n  cli.py            # CLI entry point\nscripts/            # Experiment runners + govML-generated scripts\nconfig/             # YAML configuration (agents, attacks, defenses)\ndata/tasks/         # YAML-driven attack scenarios\ndocs/               # govML governance documents (22 templates)\nblog/               # Blog draft + conference abstract + images\n```\n\n## Project Governance\n\nBuilt with [govML](https://github.com/rexcoleman/govML) v2.4 (security-ml profile, 22 templates). Key governance documents:\n\n- [`docs/PROJECT_BRIEF.md`](docs/PROJECT_BRIEF.md) — Thesis, research questions, success criteria\n- [`docs/DECISION_LOG.md`](docs/DECISION_LOG.md) — 3 architecture decision records\n- [`docs/ADVERSARIAL_EVALUATION.md`](docs/ADVERSARIAL_EVALUATION.md) — Threat model + controllability matrix\n- [`docs/PUBLICATION_PIPELINE.md`](docs/PUBLICATION_PIPELINE.md) — Blog distribution governance\n\n## License\n\nMIT\n","readmeExcerpt":"**⚠️ ARCHIVED** — This project is archived. The 7 attack classes and LLM-as-judge defense findings remain valid, but no further development is planned. Agent security research continues in $1 and $1. Agent Security Red-Team Framework Reasoning chain hijacking hits 100% success against default LangChain ReAct agents. 7 attack classes systematized — 5 absent from OWASP LLM Top 10 and MITRE ATLAS. Layered defense reduce","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"# Clone and install\ngit clone https://github.com/rexcoleman/agent-redteam-framework.git\ncd agent-redteam-framework\nconda env create -f environment.yml\nconda activate agent-redteam\npip install -e .\n\n# Set your API key\nexport ANTHROPIC_API_KEY=\"sk-ant-api03-...\"\n\n# Verify environment\nagent-redteam verify-env\n\n# Run attacks against LangChain ReAct agent\nagent-redteam scan --agent langchain_react --attack all --seed 42\n\n# Evaluate defenses\nagent-redteam defend --agent langchain_react --defense layered --seed 42\n\n# Generate figures\nagent-redteam figures"},{"language":"text","snippet":"src/\n  agents/           # Agent target abstractions (LangChain, CrewAI)\n  attacks/          # Attack class implementations\n  defenses/         # Defense layers (input sanitizer, tool boundary, layered)\n  core/             # Config, types, logging\n  cli.py            # CLI entry point\nscripts/            # Experiment runners + govML-generated scripts\nconfig/             # YAML configuration (agents, attacks, defenses)\ndata/tasks/         # YAML-driven attack scenarios\ndocs/               # govML governance documents (22 templates)\nblog/               # Blog draft + conference abstract + images"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[],"languages":["python"],"docsSourceLabel":"GITHUB OPENCLEW","editorialOverview":"Open-source security testing for LLM-based agents. 7 attack classes (5 novel beyond OWASP/ATLAS), 19 scenarios, LangChain + CrewAI support, LLM-as-judge defense layer. **⚠️ ARCHIVED** — This project is archived. The 7 attack classes and LLM-as-judge defense findings remain valid, but no further development is planned. Agent security research continues in $1 and $1. Agent Security Red-Team Framework Reasoning chain hijacking hits 100% success against default LangChain ReAct agents. 7 attack classes systematized — 5 absent from OWASP LLM Top 10 and MITRE ATLAS. Layered defense reduce","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":397,"uniquenessScore":67,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-05-18T06:45:33.847Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-05-18T06:45:33.847Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-09T01:01:01.414Z","emptyReason":null},"items":[{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-10T18:48:31.762Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/github_openclew","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}