Security

Assess AI/LLM systems for security vulnerabilities via reconnaissance and testing.

1|Updated Mar 15, 2026
One-click install
npx skills add https://github.com/GratefulJinx77/tai --skill security-gratefuljinx77
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: Security
Source: https://github.com/GratefulJinx77/tai/tree/main/.tai/skills/security
Command: npx skills add https://github.com/GratefulJinx77/tai --skill security-gratefuljinx77

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill requires promptfoo, garak, pyrit, and includes scripts (resource) and references (resource) and assets (resource) components.

What problem does it solve?

This Skill provides a comprehensive framework for security testing and intelligence gathering on AI/LLM systems, ensuring they are secure against various attack vectors and vulnerabilities.

Core Features & Use Cases

  • Security Assessment: Perform in-depth security assessments, including network reconnaissance, web app security testing, prompt injection testing, and annual report analysis.
  • Reconnaissance Methodology: Includes initial discovery, DOM extraction, JavaScript analysis, network traffic capture, API endpoint enumeration, parameter discovery, and AI/LLM component identification.
  • Testing Tools Integration: Integrates with automated testing tools like Promptfoo, Garak, and PyRIT for comprehensive coverage.
  • Use Case: Use this Skill to identify potential security vulnerabilities in your AI systems before they can be exploited by malicious actors.

Quick Start

To initiate a security assessment, run the "reconnaissance" command.

Frequently Asked Questions about Security

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform a security assessment on an AI system?

Conducting a security assessment involves network reconnaissance, web app testing, and prompt injection analysis using integrated testing tools to identify vulnerabilities in AI systems.

What is prompt injection testing for LLM security?

Prompt injection testing for LLM security is the process of evaluating AI systems against malicious inputs using automated tools like Promptfoo, Garak, and PyRIT to identify prompt manipulation vulnerabilities.

Can I use promptfoo and garak for LLM penetration testing?

Yes, you can use promptfoo and garak for LLM penetration testing. This Skill integrates with both tools, alongside PyRIT, to provide comprehensive automated coverage for prompt injection and security vulnerabilities.

What reconnaissance steps are needed for web app security testing?

Reconnaissance for web app security testing requires initial discovery, DOM extraction, JavaScript analysis, network traffic capture, API endpoint enumeration, and parameter discovery to identify AI/LLM components.

Do I need authorization to run AI security assessments?

Yes, you need explicit authorization to run AI security assessments. The framework requires permission before conducting network reconnaissance, prompt injection testing, and vulnerability scanning on target systems.