Tech riderRev. 21 Sept 2026
- 1Runs onLinux
- 2CostsNot stated by the maker
- 3Prompt injection testsYes
- 4Jailbreak testsYes
- 5Data leakage testsYes
- 6Unsafe output testsYes
- 7Custom test casesYes
- 8Deployment modeself hosted
7 lines stated Written from the maker's own pages: rdi.berkeley.edu
Overview
SuperRed is ranked #12 of 29 in AI security testing tools on Specifiction. It runs on Linux.
Compared on AI security testing tools
- Free plan
- Yesrdi.berkeley.edu
- Prompt injection tests
- Yesrdi.berkeley.edu
- Jailbreak tests
- Yesrdi.berkeley.edu
- Data leakage tests
- Yesrdi.berkeley.edu
- Unsafe output tests
- Yesrdi.berkeley.edu
- Custom test cases
- Yesrdi.berkeley.edu
- Deployment mode
- self_hostedrdi.berkeley.edu
Facts
- Purpose
- SuperRed is an open-source framework for red-teaming chatbots, agents, and assistants by testing whether attacks can violate security properties.rdi.berkeley.edu · 4 Oct 2026
- Composable components
- It treats the attacker, system under test, and benchmark as separate interchangeable modules coordinated by a controller.rdi.berkeley.edu · 4 Oct 2026
- Threat models
- Each run can define attacker model, per-task budget, trust-boundary access, and whether benchmark feedback is visible to the attacker.rdi.berkeley.edu · 4 Oct 2026
- Attacks and benchmarks
- The module catalogue lists 35 modules: 21 attackers, 6 targets, and 8 benchmarks.rdi.berkeley.edu · 4 Oct 2026
- Example modules
- Listed modules include PAIR, TAP, AutoDAN-Turbo, Crescendo, AgentVigil, HarmBench, AgentDojo, and DecodingTrust-Agent.rdi.berkeley.edu · 4 Oct 2026
- Metrics and reports
- Runs record model, cost, and success rate, with a live terminal dashboard and a web report for results.rdi.berkeley.edu · 4 Oct 2026
- Parallel runs
- The framework can run multiple threat models in parallel, each against its own system instance.rdi.berkeley.edu · 4 Oct 2026
- Installation
- The guide installs the framework with pip install superred and describes it as a Python framework whose guide assumes familiarity with Python and asyncio.rdi.berkeley.edu · 4 Oct 2026
- Model endpoints
- The example target uses a LiteLLM-compatible endpoint with a base URL and API key; the guide says most LLM-driven attackers also call models through LiteLLM.rdi.berkeley.edu · 4 Oct 2026
- Target types
- Targets can wrap fixed-response fixtures, simulated environments, sandboxes, or live deployments.rdi.berkeley.edu · 4 Oct 2026
- Security scope
- The controller filters which controllables, observables, trajectory entries, and evaluation sub-scores the optimizer can access according to the configured scope.rdi.berkeley.edu · 4 Oct 2026
- Sensitive results
- Persisted trajectories are not scrubbed and may contain jailbreaks, planted secrets, and exfiltrated content; API keys and API base URLs are not written in the serialized LLM configuration.rdi.berkeley.edu · 4 Oct 2026
- Intended users
- The project describes use by red-teamers, system builders, and evaluators, and its guide covers wrapping systems, writing attackers, defining success criteria, and running evaluations.rdi.berkeley.edu · 4 Oct 2026
- Maker
- The site says SuperRed was made at the University of California, Berkeley.rdi.berkeley.edu · 4 Oct 2026
- Composable modules
- It keeps attackers, systems under test, and security claims as interchangeable modules coordinated by a controller.rdi.berkeley.edu · 4 Oct 2026
- Evaluation reports
- Runs record model, cost, and success rate; the framework provides live progress and browsable reports with per-task details and trajectories.rdi.berkeley.edu · 4 Oct 2026
- Scale
- The controller can run many threat models in parallel, each against its own system instance.rdi.berkeley.edu · 4 Oct 2026
- Supported targets
- Targets can wrap fixed-response fixtures, simulated environments, sandboxes, or live deployments, and the guide recommends staging or throwaway instances for real systems.rdi.berkeley.edu · 4 Oct 2026
- Integration
- The getting-started example connects to any LiteLLM-compatible model endpoint using a base URL and API key.rdi.berkeley.edu · 4 Oct 2026
- Security controls
- The controller filters attacker-visible and injectable surfaces according to security-domain scopes and can cap attacker model spend per task.rdi.berkeley.edu · 4 Oct 2026
- Requirements
- The package requires Python 3.11 through 3.13; Python 3.14 is not supported.pypi.org · 4 Oct 2026
- License and maturity
- PyPI lists the package under the MIT license and classifies its development status as Alpha.pypi.org · 4 Oct 2026
- Intended audience
- The getting-started guide is for people who can read Python and have seen asyncio, and PyPI lists Science/Research as an intended audience.rdi.berkeley.edu · 4 Oct 2026
Best SuperRed alternatives
See all 12 All accessCh 01 F5 BIG-IP APM Free trialAndroidAPI 7.7 All accessCh 02 OpenSecureAI Scanner Free planAPILinux from $49/mo7.4 All accessCh 03 Project Moonshot Free planAPILinux Free to start7.4 All accessCh 04 AIRTA Red Team Free planAPILinux Free to start7.3 All accessCh 05 Promptfoo Free planAPILinux Free to start7.3 All accessCh 06 PromptGuard Free planAPIBrowser from $19/mo7.3
Where it ranks on Specifiction
Is SuperRed yours?
Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.
Sources
- rdi.berkeley.edu/superred/· checked 4 Oct 2026
- rdi.berkeley.edu/superred/modules· checked 4 Oct 2026
- rdi.berkeley.edu/superred/guide/· checked 4 Oct 2026
- rdi.berkeley.edu/superred/reference/· checked 4 Oct 2026
- rdi.berkeley.edu/superred/reference/results· checked 4 Oct 2026
- rdi.berkeley.edu/superred/reference/controller· checked 4 Oct 2026
- pypi.org/project/superred/· checked 4 Oct 2026


