testing-methodologies

Structure AI security testing across reconnaissance, threat modeling, and reporting.

3|Updated Nov 18, 2025
One-click install
npx skills add https://github.com/pluginagentmarketplace/custom-plugin-ai-red-teaming --skill testing-methodologies
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: testing-methodologies
Source: https://github.com/pluginagentmarketplace/custom-plugin-ai-red-teaming/tree/main/skills/testing-methodologies
Command: npx skills add https://github.com/pluginagentmarketplace/custom-plugin-ai-red-teaming --skill testing-methodologies

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) and assets (resource) components.

What problem does it solve?

This Skill provides a structured, repeatable approach to AI security testing across the entire lifecycle—from reconnaissance and threat modeling to vulnerability assessment, exploitation, and reporting—so teams can identify and remediate risks efficiently.

Core Features & Use Cases

  • Threat Modeling: Apply frameworks like STRIDE, threat trees, and MITRE ATLAS mappings to identify and prioritize AI-system risks.
  • Vulnerability Testing: Systematically test input handling, output safety, model robustness, and access control with predefined categories and artifacts.
  • Exploitation & Reporting: Develop PoCs, assess impact, and generate comprehensive security reports with remediation roadmaps for governance and compliance.
  • Use Case: A data science team uses this methodology to conduct a full security assessment of an AI assistant before deployment, ensuring controls are in place.

Quick Start

Use the testing-methodologies skill to generate a full security testing plan for an AI assistant. Then review the included threat modeling templates and test plans to customize for your environment. If needed, adapt the scope to reconnaissance, threat modeling, vulnerability testing, exploitation, and reporting.

Frequently Asked Questions about testing-methodologies

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform structured AI security testing across the full lifecycle?

Structured AI security testing applies repeatable methodologies across reconnaissance, threat modeling, vulnerability assessment, exploitation, and reporting to identify and remediate risks efficiently.

Can I map AI threat modeling results to MITRE ATLAS and OWASP-LLM frameworks?

Yes, AI threat modeling supports mapping identified risks to MITRE ATLAS techniques and OWASP-LLM categories, ensuring assessments align with recognized security frameworks for auditable reporting.

What is the best way to test AI model robustness and input handling vulnerabilities?

Vulnerability testing systematically evaluates input handling, output safety, model robustness, and access control using predefined categories and artifacts to uncover AI system weaknesses.

How do I generate a security assessment report for an AI assistant before deployment?

Exploitation and reporting phases develop proof-of-concepts, assess impact, and generate comprehensive security reports with remediation roadmaps to validate controls before AI deployment.

Does this security testing methodology support STRIDE and attack trees?

Yes, threat modeling applies frameworks like STRIDE and attack trees to identify, analyze, and prioritize AI-system risks during the security assessment process.

How do I assess API and deployment environment risks for AI systems?

AI security testing applies structured methodologies across model development, API, and deployment environments to perform reconnaissance and vulnerability testing on exposed AI surfaces.