scaffolding-red-team-engagement

Scaffold AI red-team engagement documents including Rules of Engagement, scope, kill-switch, logging, and disclosure.

2|Updated May 23, 2026
One-click install
npx skills add https://github.com/rocklambros/rcs --skill scaffolding-red-team-engagement
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: scaffolding-red-team-engagement
Source: https://github.com/rocklambros/rcs/tree/main/skills/security/scaffolding-red-team-engagement
Command: npx skills add https://github.com/rocklambros/rcs --skill scaffolding-red-team-engagement

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill helps teams formalize an AI red-team engagement before any attack traffic starts, preventing scope drift, missing authorization, and weak evidence handling.

Core Features & Use Cases

  • Rules of Engagement Scaffolding: Produces a ready-to-sign RoE with parties, time window, authorization boundaries, and signature requirements.
  • Scope and Safety Controls: Enumerates in-scope assets and explicit out-of-scope targets, including prohibited exfiltration and denial-of-service patterns.
  • Kill-Switch and Logging: Defines halt authority, halt mechanisms, preservation steps, and tamper-evident append-only logging for every attempt.
  • Reporting and Disclosure: Adds final-report structure, safe-harbor language, and coordinated-disclosure timing for accountable engagements.

Quick Start

Ask the skill to scaffold the engagement for your target system, including the RoE, scope, kill-switch, logging, and disclosure materials.

Frequently Asked Questions about scaffolding-red-team-engagement

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is an AI red-team engagement rules of engagement document?

An AI red-team engagement rules of engagement document formalizes parties, time windows, authorization boundaries, and signature requirements before testing begins. This scaffolding produces a ready-to-sign RoE to prevent scope drift and missing authorization.

How do I set up a kill-switch protocol for LLM red-teaming?

To set up a kill-switch protocol for LLM red-teaming, define halt authority, halt mechanisms, and preservation steps. This scaffolding generates the protocol to safely stop attack traffic during agentic system or chatbot assessments.

What should be included in scope inventory for red-teaming AI applications?

Scope inventory for red-teaming AI applications must include explicit in-scope assets and out-of-scope targets, specifically prohibiting exfiltration and denial-of-service patterns. This generates the enumeration to maintain strict authorization boundaries.

How do I create a tamper-evident logging template for AI security testing?

You create a tamper-evident logging template for AI security testing by defining append-only logs for every attack attempt. This scaffolding provides the logging template to ensure weak evidence handling is avoided during regulatory assessments.

Does AI red-team scaffolding work for bug-bounty and regulatory assessments?

AI red-team scaffolding works for paid, internal, bug-bounty, and regulatory assessments of deployed LLM applications and agentic systems. It requires signed time-bounded authorization and a pre-flight gate blocking attack traffic until approval.

Why do I need coordinated-disclosure language for AI red-team engagements?

You need coordinated-disclosure language for AI red-team engagements to establish safe-harbor terms and accountable reporting timelines. This scaffolding adds final-report structure and disclosure timing to ensure responsible vulnerability reporting.