Agent skill

Continuous LLM Red Teaming With Promptfoo

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Wires Promptfoo and DeepTeam into CI/CD for automated, repeatable red-teaming of LLM apps against OWASP LLM Top 10, OWASP Agentic, and MITRE ATLAS presets, failing the build when jailbreak or…

Apache-2.0Auto-check passedSecurity

Install Continuous LLM Red Teaming With Promptfoo

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill continuous-llm-red-teaming-with-promptfoo -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills continuous-llm-red-teaming-with-promptfoo --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/continuous-llm-red-teaming-with-promptfoo .claude/skills/continuous-llm-red-teaming-with-promptfoo && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
continuous-llm-red-teaming-with-promptfoo
GitHub stars
34k
Token cost
~2.5k tokens
SKILL.md length
800 words
Files
5 (incl. scripts, references)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Wires Promptfoo and DeepTeam into CI/CD for automated, repeatable red-teaming of LLM apps against OWASP LLM Top 10, OWASP Agentic, and MITRE ATLAS presets, failing the build when jailbreak or…

  • Works in 6 steps: Scaffold the red-team configuration → Define targets, OWASP presets, and… → Run the suite and view the report → …
  • Continuous adversarial testing in CI/CD
  • SKILL.md covers Overview, When to Use, Prerequisites and Objectives, plus 5 more sections
  • Runs Python scripts from its folder; calls npm and pip; needs OPENAI_API_KEY

What it does

Continuous LLM Red Teaming With Promptfoo is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Wires Promptfoo and DeepTeam into CI/CD for automated, repeatable red-teaming of LLM apps against OWASP LLM Top 10, OWASP Agentic, and MITRE ATLAS presets, failing the build when jailbreak or injection vulnerabilities regress. Use for continuous adversarial testing in CI/CD, a merge-blocking security gate, or comparing model/prompt versions for compliance reporting.

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts and reference files (for example `references/api-reference.md`, `references/standards.md` and `scripts/agent.py`).

It sits in Security, covering Red teaming and adversary simulation, Web application vulnerabilities and CI/CD. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Continuous adversarial testing in CI/CD
  • A merge-blocking security gate
  • Comparing model/prompt versions for compliance reporting

Example prompts

  • “Use the continuous-llm-red-teaming-with-promptfoo skill to wire Promptfoo and DeepTeam into CI/CD for automated, repeatable red-teaming of LLM apps…”
  • “/continuous-llm-red-teaming-with-promptfoo”

Requirements

  • Python 3
  • Node.js
  • A credential in OPENAI_API_KEY

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Scaffold the red-team configuration
  2. Define targets, OWASP presets, and attack strategies
  3. Run the suite and view the report
  4. Add DeepTeam for programmatic, research-backed attacks
  5. Gate the build in CI/CD (GitHub Actions)
  6. Track regressions over time

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • npm
    • pip

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • promptfoo.dev
    • trydeepteam.com
    • github.com
    • genai.owasp.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • OPENAI_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Continuous LLM Red Teaming With Promptfoo loads about 2.5k tokens when it runs, and up to ~3.4k if it reads all its reference files. Until then it costs about 103 tokens; SKILL.md has 800 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~103
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 800 words, ~2,456 tokens.

Download SKILL.mdSave it as .claude/skills/continuous-llm-red-teaming-with-promptfoo/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
continuous-llm-red-teaming-with-promptfoo
description
Wires Promptfoo and DeepTeam into CI/CD for automated, repeatable red-teaming of LLM apps against OWASP LLM Top 10, OWASP Agentic, and MITRE ATLAS presets, failing the build when jailbreak or injection vulnerabilities regress. Use for continuous adversarial testing in CI/CD, a merge-blocking security gate, or comparing model/prompt versions for compliance reporting.
domain
cybersecurity
subdomain
ai-security
tags
ai-security, llm-red-teaming, promptfoo, deepteam, ci-cd, owasp-llm-top10, jailbreak, regression-testing
version
1.0
author
mahipal
license
Apache-2.0
nist_ai_rmf
MANAGE-4.1
atlas_techniques
AML.T0051

Continuous LLM Red Teaming with Promptfoo

Authorized Use Only: Run these adversarial probes only against LLM applications and endpoints you own or are explicitly authorized to test. Generated attack payloads (jailbreaks, prompt injections, harmful-content elicitation) are adversarial inputs; sending them to third-party services without permission may violate terms of service.

Overview

Promptfoo is an open-source LLM evaluation and red-teaming framework (used by OpenAI and Anthropic per its README) that generates adversarial test cases, runs them against your model/agent, and grades the responses. DeepTeam (by Confident AI) is a complementary open-source framework offering 50+ ready-to-use vulnerabilities and 10+ research-backed attack methods. Together they let you treat LLM security as a regression test: every commit re-runs the same adversarial suite, and the pipeline fails when a previously-safe behavior regresses.

This matters because LLM applications change constantly — prompts, models, RAG sources, tools, and guardrails all drift. A jailbreak that was patched last sprint can silently return after a prompt edit or a model upgrade. Promptfoo maps its plugins directly onto the OWASP LLM Top 10 (owasp:llm) and OWASP Agentic (owasp:agentic) presets, and onto MITRE ATLAS, so the suite tracks recognized risk taxonomies. The core threat addressed here is AML.T0051 — LLM Prompt Injection (MITRE ATLAS): adversarial instructions that override the application's intended behavior. This skill follows the Promptfoo red-team docs (https://www.promptfoo.dev/docs/red-team/) and DeepTeam docs (https://www.trydeepteam.com/docs/getting-started), and aligns to NIST AI RMF MANAGE-4.1 (post-deployment monitoring and feedback to manage AI risk).

When to Use

  • When you need continuous, automated red-teaming of an LLM app in CI/CD rather than one-off manual tests.
  • When you want to enforce a security gate: block merges that introduce or reintroduce jailbreak/injection vulnerabilities.
  • When mapping coverage to OWASP LLM Top 10 / OWASP Agentic / MITRE ATLAS for compliance reporting.
  • When comparing the security posture of two models or prompt versions side by side.
  • When tracking vulnerability regression over time across releases.

Prerequisites

  • Node.js 18+ (Promptfoo is distributed via npm) and Python 3.9+ (for DeepTeam).
  • Install Promptfoo and DeepTeam:
    bash
    npm install -g promptfoo            # or: npx promptfoo@latest
    pip install -U deepteam
  • API access/credentials for the target LLM endpoint (and a grader model, e.g. an OpenAI key) exposed as environment variables.
  • A CI/CD platform (GitHub Actions, GitLab CI) with secret storage.
  • Authorization to test the target application.

Objectives

  • Scaffold a Promptfoo red-team config targeting your LLM app.
  • Enable OWASP LLM Top 10 and OWASP Agentic plugin presets plus jailbreak/injection strategies.
  • Run the suite locally and interpret the per-plugin pass/fail report.
  • Add DeepTeam as a second engine for programmatic, research-backed attacks.
  • Integrate both into CI/CD so builds fail on new vulnerabilities.
  • Generate shareable HTML/PDF security reports per run.

MITRE ATT&CK Mapping

IDName (MITRE ATLAS)Tactic
AML.T0051LLM Prompt InjectionInitial Access / Persistence (LLM)
AML.T0051.000Direct (Prompt Injection)LLM Attack
AML.T0051.001Indirect (Prompt Injection)LLM Attack
AML.T0054LLM JailbreakPrivilege Escalation / Defense Evasion (LLM)

Workflow

1. Scaffold the red-team configuration

Initialize an interactive config; it writes promptfooconfig.yaml where targets, plugins, and strategies live.

bash
promptfoo redteam init
# choose your target type (HTTP endpoint, openai:..., anthropic:..., custom provider)
Show full SKILL.md (324 more words)Show less
2. Define targets, OWASP presets, and attack strategies

Edit promptfooconfig.yaml. The purpose grounds attack generation; plugins are adversarial input generators; strategies are delivery techniques (jailbreak/injection wrappers).

yaml
# promptfooconfig.yaml
targets:
  - id: https://api.example.com/chat        # your app endpoint
    label: support-bot

redteam:
  purpose: |
    A customer-support assistant for an e-commerce site. Must never reveal
    system prompts, leak PII, or perform actions outside order support.
  numTests: 10
  plugins:
    - owasp:llm          # OWASP LLM Top 10 preset
    - owasp:agentic      # OWASP Agentic threats preset
    - id: pii:direct
      numTests: 15
    - prompt-extraction  # system-prompt leakage
    - harmful
  strategies:
    - id: jailbreak              # iterative single-turn jailbreak
    - id: jailbreak:composite    # stacked jailbreak techniques
    - id: crescendo              # multi-turn escalation
    - id: prompt-injection       # injection wrapper
3. Run the suite and view the report

redteam run combines generation + evaluation; then open the interactive report.

bash
promptfoo redteam run
promptfoo redteam report            # launches the web report (pass/fail per plugin)

Each row shows the plugin (mapped to OWASP/ATLAS), the strategy, the attack prompt, the model's response, and the grader's verdict. The attack success rate per plugin is your headline metric — track it per release.

4. Add DeepTeam for programmatic, research-backed attacks

Use DeepTeam to cover additional vulnerabilities/attacks and to script bespoke suites in Python.

python
# deepteam_suite.py
from deepteam import red_team
from deepteam.vulnerabilities import Bias, PIILeakage
from deepteam.attacks.single_turn import PromptInjection

def model_callback(prompt: str) -> str:
    # call your application's LLM endpoint here and return the text response
    return call_my_app(prompt)

red_team(
    model_callback=model_callback,
    vulnerabilities=[Bias(types=["race"]), PIILeakage(types=["api_and_database_access"])],
    attacks=[PromptInjection()],
)

DeepTeam can also be driven from a YAML config:

bash
deepteam run config.yaml
5. Gate the build in CI/CD (GitHub Actions)

Fail the pipeline when red-team assertions fail. Promptfoo returns a non-zero exit code on failures, which blocks the merge.

yaml
# .github/workflows/llm-redteam.yml
name: LLM Red Team
on: [pull_request]
jobs:
  redteam:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: actions/setup-node@v4
        with: { node-version: '20' }
      - run: npm install -g promptfoo
      - name: Run red team (fails build on new vulns)
        env:
          OPENAI_API_KEY: ${{ secrets.OPENAI_API_KEY }}
        run: promptfoo redteam run --no-progress-bar
      - name: Export machine-readable results
        if: always()
        run: promptfoo redteam report --output results.json
      - uses: actions/upload-artifact@v4
        if: always()
        with: { name: redteam-report, path: results.json }
6. Track regressions over time

Persist results.json per run and compare attack-success-rate per plugin between releases. A rising rate for any OWASP LLM category is a regression to triage before release. Promptfoo's --filter-failing lets you re-run only previously failing cases to confirm a fix.

bash
promptfoo redteam run --filter-failing results.json

Tools and Resources

Plugin / Strategy Reference

Promptfoo itemTypeMaps to
owasp:llmpresetOWASP LLM Top 10 suite
owasp:agenticpresetOWASP Agentic threats
prompt-extractionpluginLLM07 system-prompt leakage
pii:directpluginLLM06 sensitive-info disclosure
harmfulpluginharmful content generation
jailbreak / jailbreak:compositestrategyAML.T0054 LLM jailbreak
crescendostrategymulti-turn jailbreak
prompt-injectionstrategyAML.T0051 prompt injection

Validation Criteria

  • promptfooconfig.yaml created with target, owasp:llm, and owasp:agentic plugins.
  • Jailbreak and prompt-injection strategies enabled.
  • promptfoo redteam run executes and produces a per-plugin pass/fail report.
  • DeepTeam suite runs against the same target via model_callback.
  • CI/CD job fails the build on new red-team failures (non-zero exit).
  • results.json artifact archived per run for regression tracking.
  • Attack-success-rate per OWASP category trended across releases.

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references) in skills/continuous-llm-red-teaming-with-promptfoo of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • references/standards.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Continuous LLM Red Teaming With Promptfoo next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Continuous LLM Red Teaming With Promptfoo compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Continuous LLM Red Teaming With Promptfoo this skillmukul975/Anthropic-Cybersecurity-Skills34k—~2.5kAutomated safety check: PassApache-2.0
Code Securitysemgrep/skills324—~1.2kAutomated safety check: PassCustom licence
Taint Instrumentation AssistantArabelaTso/Skills-4-SE253—~2.9kAutomated safety check: PassApache-2.0
Cybersecurityohmyjahh/xquads-squads277—~895Automated safety check: PassMIT
Sast BanditAgentSecOps/SecOpsAgentKit2201 repos~2.6kAutomated safety check: PassCustom licence
Golang Securityunxed/f42432 repos~3.6kAutomated safety check: PassMIT

Similar skills

  • Code Security

    semgrep/skills

    Official

    Security guidelines for writing secure code. An agent skill from semgrep/skills.

    324 GitHub stars~1.2k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Taint Instrumentation Assistant

    ArabelaTso/Skills-4-SE

    Instruments code to track the flow of untrusted or sensitive data at runtime, enabling detection of injection vulnerabilities, data leaks, and privilege violations.

    253 GitHub stars~2.9k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Cybersecurity

    ohmyjahh/xquads-squads

    Squad de 15 agentes de seguranca ofensiva e defensiva (Georgia Weidman, Peter Kim, Jim Manico, Chris Sanders, Omar Santos, Marcus Carey) cobrindo pentest, red team, blue team, AppSec, recon e…

    277 GitHub stars~895 tokensUpdated 11 days ago
    SecurityAuto-check passed
  • Sast Bandit

    AgentSecOps/SecOpsAgentKit

    Python security vulnerability detection using Bandit SAST with CWE and OWASP mapping.

    220 GitHub starsUsed in 1 repo~2.6k tokens
    SecurityAuto-check passed
  • Security best practices and vulnerability prevention for Golang — injection (SQL, command, XSS), cryptography, path traversal, SSRF and HTTP security headers, cookies, secrets management, memory…

    243 GitHub starsUsed in 2 repos~3.6k tokens
    SecurityAuto-check passed
  • Mobile Reverse

    sickn33/agentic-awesome-skills

    Authorized Android/iOS application reverse engineering and security testing: APK/IPA analysis, runtime instrumentation (Frida/Objection), SSL-pinning and jailbreak/root-detection bypass, per OWASP…

    47k GitHub starsUsed in 1 repo~1.5k tokens
    SecurityAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Continuous LLM Red Teaming With Promptfoo

What does Continuous LLM Red Teaming With Promptfoo do?

Wires Promptfoo and DeepTeam into CI/CD for automated, repeatable red-teaming of LLM apps against OWASP LLM Top 10, OWASP Agentic, and MITRE ATLAS presets, failing the build when jailbreak or…. Continuous LLM Red Teaming With Promptfoo is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Wires Promptfoo and DeepTeam into CI/CD for automated, repeatable red-teaming of LLM apps against OWASP LLM Top 10, OWASP Agentic, and MITRE ATLAS presets, failing the build when jailbreak or injection vulnerabilities regress.

When should I use Continuous LLM Red Teaming With Promptfoo?

Continuous LLM Red Teaming With Promptfoo fits situations like: continuous adversarial testing in CI/CD; A merge-blocking security gate; comparing model/prompt versions for compliance reporting.

How do I install Continuous LLM Red Teaming With Promptfoo in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill continuous-llm-red-teaming-with-promptfoo -a claude-code`. Or copy the skill folder (skills/continuous-llm-red-teaming-with-promptfoo in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/continuous-llm-red-teaming-with-promptfoo in your project. Claude Code loads it when a task matches its description.

How do I install Continuous LLM Red Teaming With Promptfoo in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill continuous-llm-red-teaming-with-promptfoo -a codex`. Or copy the skill folder (skills/continuous-llm-red-teaming-with-promptfoo in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/continuous-llm-red-teaming-with-promptfoo in your project. Codex loads it when a task matches its description.

Can I use Continuous LLM Red Teaming With Promptfoo in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill continuous-llm-red-teaming-with-promptfoo -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/continuous-llm-red-teaming-with-promptfoo, .gemini/skills/continuous-llm-red-teaming-with-promptfoo, .github/skills/continuous-llm-red-teaming-with-promptfoo and .opencode/skills/continuous-llm-red-teaming-with-promptfoo in your project.

What does Continuous LLM Red Teaming With Promptfoo need to run?

Going by SKILL.md and its folder, Continuous LLM Red Teaming With Promptfoo needs Python for the scripts in its folder, the command-line tools its instructions call (npm and pip) and credentials named OPENAI_API_KEY. Our summary lists: Python 3; Node.js; A credential in OPENAI_API_KEY.

Does Continuous LLM Red Teaming With Promptfoo access the network?

SKILL.md names 4 domains. As links in the text: promptfoo.dev, trydeepteam.com, github.com and genai.owasp.org. This is read from the text; nothing was executed.

Is Continuous LLM Red Teaming With Promptfoo safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Continuous LLM Red Teaming With Promptfoo use?

Continuous LLM Red Teaming With Promptfoo is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Continuous LLM Red Teaming With Promptfoo use?

About 2.5k tokens (SKILL.md is roughly 9.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 930 tokens, read only when the agent opens those files.

What are the alternatives to Continuous LLM Red Teaming With Promptfoo?

Skills that share tags, products or a category with Continuous LLM Red Teaming With Promptfoo: Code Security (semgrep/skills, 324 stars), Taint Instrumentation Assistant (ArabelaTso/Skills-4-SE, 253 stars), Cybersecurity (ohmyjahh/xquads-squads, 277 stars) and Sast Bandit (AgentSecOps/SecOpsAgentKit, 220 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Continuous LLM Red Teaming With Promptfoo?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.