ai-threat-testing

Identify and remediate AI security vulnerabilities in LLM applications.

Updated Apr 23, 2026
One-click install
npx skills add https://github.com/YukiIto1999/ctf-sleuth --skill ai-threat-testing
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: ai-threat-testing
Source: https://github.com/YukiIto1999/ctf-sleuth/tree/main/.claude/skills/ai-threat-testing
Command: npx skills add https://github.com/YukiIto1999/ctf-sleuth --skill ai-threat-testing

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Offensive AI security testing aims to identify and remediate vulnerabilities in LLM-based systems, including prompt manipulation, unsafe outputs, data exposure, and supply-chain risks, to prevent real-world abuse before attackers can exploit them.

Core Features & Use Cases

  • 10 specialized agents addressing each OWASP LLM vulnerability (prompt injection, output handling, training poisoning, resource exhaustion, supply chain, excessive agency, model extraction, vector poisoning, overreliance, and logging bypass).
  • Structured workflows from reconnaissance to evidence collection and reporting, enabling repeatable security assessments.
  • Authorized testing framework with remediation-oriented results, suitable for red-team exercises, vendor risk reviews, and internal security audits.

Quick Start

Initiate an authorized AI security assessment across all ten OWASP LLM vulnerabilities for the target application.

Frequently Asked Questions about ai-threat-testing

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I test LLM applications for OWASP security vulnerabilities?

To test LLM applications for OWASP security vulnerabilities, systematically assess prompt injection, output handling, and supply chain risks using specialized agents. This process identifies and remediates threats through structured workflows spanning reconnaissance to evidence collection.

What is AI threat modeling for prompt injection and how does it work?

AI threat modeling for prompt injection identifies how malicious inputs manipulate LLM behavior to bypass safety controls. It works by systematically testing authorized environments to document vulnerabilities, collect evidence, and generate remediation guidance against such attacks.

Can I use this AI security assessment for red-team exercises and vendor risk reviews?

Yes, you can use this AI security assessment for red-team exercises and vendor risk reviews. The authorized testing framework provides repeatable workflows and remediation-oriented results suitable for internal audits and evaluating external LLM applications.

Does pentesting LLM applications require documented testing authorization?

Yes, pentesting LLM applications requires documented testing authorization and controlled environments. These prerequisites ensure comprehensive evidence collection and security assessments are conducted safely without disrupting actual LLM services.

How do I remediate excessive agency and model extraction risks in LLM systems?

To remediate excessive agency and model extraction risks in LLM systems, apply targeted assessments to identify specific vulnerabilities. Structured reporting then provides actionable remediation guidance to prevent unauthorized actions and model theft.