Tech riderRev. 21 Sept 2026
- 1Runs onself-hosted
- 2CostsNot stated by the maker
- 3Attack categoriesprompt injection
- 4Target systemsLLM-integrated applications
- 5Automation levelautomated
- 6Custom testsYes
- 7Deploymentself hosted
- 8Continuous monitoringNo
7 lines stated Written from the maker's own pages: github.com

Overview
HouYi is ranked #23 of 27 in AI red teaming tools on Specifiction. It runs on Self-hosted.
Compared on AI red teaming tools
- Attack categories
- prompt injectiongithub.com
- Target systems
- LLM-integrated applicationsgithub.com
- Automation level
- automatedgithub.com
- Custom tests
- Yesgithub.com
- Deployment
- self_hostedgithub.com
- Continuous monitoring
- Nogithub.com
Facts
- Purpose
- HouYi is an automated prompt injection framework for LLM-integrated applications.github.com · 8 Oct 2026
- Research package
- The repository provides source code for the framework and a demo script that simulates an LLM-integrated application.github.com · 8 Oct 2026
- Attack method
- HouYi automatically injects prompts into LLM-integrated applications to attack them.github.com · 8 Oct 2026
- Custom applications
- Users can target real-world LLM-integrated applications by writing their own harness and attack intention.github.com · 8 Oct 2026
- Demo
- The included demo simulates an English-to-French translation application and demonstrates an injection that appends “Pwned!!” to responses.github.com · 8 Oct 2026
- Setup
- The README says to install the requirements and have Python 3.8 or later.github.com · 8 Oct 2026
- Model requirement
- The README says HouYi is based on GPT and requires an OpenAI key in its configuration to use it.github.com · 8 Oct 2026
- Integration approach
- A user-created harness must implement interaction with the target LLM-integrated application and return its response.github.com · 8 Oct 2026
- Example integration
- The repository includes a BotSonic harness example for WriteSonic.github.com · 8 Oct 2026
- License
- The repository identifies its license as Apache-2.0.github.com · 8 Oct 2026
- Intended users
- The README asks users who use the code in research to cite the associated paper, “Prompt Injection attack against LLM-integrated Applications.”github.com · 8 Oct 2026
- Support
- The README lists contributor contact emails for Yi Liu and Gelei Deng.github.com · 8 Oct 2026
- Custom targets
- Users can target real-world LLM-integrated applications by writing their own harness and attack intention.github.com · 8 Oct 2026
- Harness
- A harness interacts with the target application and returns its response to a prompt injection.github.com · 8 Oct 2026
- LLM dependency
- The README says HouYi is based on GPT and requires an OpenAI API key in its configuration file.github.com · 8 Oct 2026
- Research finding
- The paper reports testing HouYi on 36 real LLM-integrated applications and finding 31 susceptible to prompt injection.arxiv.org · 8 Oct 2026
- Mitigation context
- The paper says its investigation discusses possible tactics for mitigating prompt injection risks.arxiv.org · 8 Oct 2026
- Contributor contact
- The README lists contributor email addresses for Yi Liu and Gelei Deng.github.com · 8 Oct 2026
Best HouYi alternatives
See all 20 All accessCh 01 F5 BIG-IP APM Free trialAndroidAPI 7.7 All accessCh 02 AgentSeal Free planAPILinux Free to start7.4 All accessCh 03 OpenSecureAI Scanner Free planAPILinux from $49/mo7.4 All accessCh 04 Promptfoo Free planAPILinux Free to start7.3 All accessCh 05 RedAmon Free planAPILinux Free to start7.3 All accessCh 06 RedLens AI Free planFree trialAPI from $199/mo7.3
Where it ranks on Specifiction
- Best AI Red Teaming Tools in 2026#23 of 27
Is HouYi yours?
Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.
Sources
- github.com/LLMSecurity/HouYi· checked 8 Oct 2026
- github.com/LLMSecurity/HouYi/blob/master/README.md· checked 8 Oct 2026
- arxiv.org/abs/2306.05499· checked 8 Oct 2026

