AI Skill Hub 强烈推荐:LLM安全评估框架 是一款优质的AI工具。AI 综合评分 8.0 分,在同类工具中表现稳健。如果你正在寻找可靠的AI工具解决方案,这是一个值得深入了解的选择。
LLM安全评估框架 是一款基于 Python 开发的开源工具,专注于 ai安全、对抗性攻击、网络安全 等核心功能。作为 GitHub 开源项目,它拥有活跃的社区支持和持续的版本迭代,代码完全透明可审计,支持本地部署以保护数据隐私。无论是个人使用还是集成到企业工作流,都能提供稳定可靠的解决方案。
LLM安全评估框架 是一款基于 Python 开发的开源工具,专注于 ai安全、对抗性攻击、网络安全 等核心功能。作为 GitHub 开源项目,它拥有活跃的社区支持和持续的版本迭代,代码完全透明可审计,支持本地部署以保护数据隐私。无论是个人使用还是集成到企业工作流,都能提供稳定可靠的解决方案。
# 方式一:pip 安装(推荐)
pip install llm-security-assessment-framework
# 方式二:虚拟环境安装(推荐生产环境)
python -m venv .venv
source .venv/bin/activate # Windows: .venv\Scripts\activate
pip install llm-security-assessment-framework
# 方式三:从源码安装(获取最新功能)
git clone https://github.com/Coff0xc/LLM-Security-Assessment-Framework
cd LLM-Security-Assessment-Framework
pip install -e .
# 验证安装
python -c "import llm_security_assessment_framework; print('安装成功')"
# 命令行使用
llm-security-assessment-framework --help
# 基本用法
llm-security-assessment-framework input_file -o output_file
# Python 代码中调用
import llm_security_assessment_framework
# 示例
result = llm_security_assessment_framework.process("input")
print(result)
# llm-security-assessment-framework 配置文件示例(config.yml) app: name: "llm-security-assessment-framework" debug: false log_level: "INFO" # 运行时指定配置文件 llm-security-assessment-framework --config config.yml # 或通过环境变量配置 export LLM_SECURITY_ASSESSMENT_FRAMEWORK_API_KEY="your-key" export LLM_SECURITY_ASSESSMENT_FRAMEWORK_OUTPUT_DIR="./output"
仓库侧栏描述建议:
面向报告交付的 LLM 安全评估框架,用于生成可复现红队套件、证据包、QA 回执、Schema 合约和可校验归档。
建议 Topics:
llm-security, ai-red-team, prompt-injection, jailbreak, owasp-llm, mcp-security, agent-security, security-reporting, risk-register, audit-evidence, json-schema, pytest, python
<a id="citation"></a>
Suggested repository description:
Report-first LLM security assessment framework for reproducible red-team suites, evidence packs, QA receipts, schemas, and archive verification.
Suggested topics:
llm-security, ai-red-team, prompt-injection, jailbreak, owasp-llm, mcp-security, agent-security, security-reporting, risk-register, audit-evidence, json-schema, pytest, python
| 能力 | 说明 |
|---|---|
| Report suites | YAML suite、内联/导入用例、响应缓存、确定性种子、策略门禁、运行前预检。 |
| Report artifacts | Markdown/HTML 报告、执行摘要、证据 CSV、case matrix、风险登记、覆盖率摘要、发布说明、bundle index。 |
| Evidence integrity | JSON Schema、制品 manifest、SHA256/大小校验、跨制品一致性校验、脱敏发布泄漏检查。 |
| Handoff QA | QA receipt JSON/Markdown、验收准则、评审决策、owner/due date、严格交接门禁。 |
| Assessment coverage | Prompt Injection、越狱角色扮演、系统提示泄漏、敏感信息/PII、Agent/MCP/工具策略风险、模型制品信号。 |
| Baseline engine | FORGEDAN、AutoDAN、PAIR、GCG、Crescendo、TAP、模型适配器、WebScan、CLI、REST API、Vue dashboard。 |
<a id="cli-reference"></a> <a id="cli-reference--常用-cli"></a> <a id="zh-cli"></a>
| Area | What it does |
|---|---|
| Report suites | YAML suite definitions, inline or imported cases, replay caches, deterministic seeds, policy gates, and preflight readiness checks. |
| Report artifacts | Markdown/HTML reports, executive summaries, evidence CSVs, case matrices, risk registers, coverage summaries, release notes, and bundle indexes. |
| Evidence integrity | JSON Schemas, artifact manifests, SHA256/size checks, cross-artifact consistency, and redacted-publication leak checks. |
| Handoff QA | QA receipt JSON/Markdown, acceptance criteria, reviewer decisions, owner/due-date tracking, and strict handoff gates. |
| Assessment coverage | Prompt injection, jailbreak roleplay, system prompt leakage, secrets/PII exposure, Agent/MCP/tool policy risk, and model artifact signals. |
| Baseline engine | FORGEDAN, AutoDAN, PAIR, GCG, Crescendo, TAP, model adapters, WebScan, CLI, REST API, and Vue dashboard. |
<a id="en-cli"></a>
pip install -e ".[web]"
pip install -e ".[all]"
pip install -e ".[web]"
| 项目 | 要求 |
|---|---|
| Python | Python >= 3.9 |
| Git | 克隆仓库和管理本地变更需要 Git |
| Node.js | Node.js >= 18,仅运行 Vue dashboard 时需要 |
```bash git clone https://github.com/Coff0xc/LLM-Security-Assessment-Framework.git cd LLM-Security-Assessment-Framework
pip install -e .
pip install -e .
cd frontend npm install npm run build ```
下面截图来自 examples/ready-for-handoff-suite.yml 生成并提交到仓库的样例报告包。完整样例见 docs/sample-report-pack/ready-for-handoff。



<a id="quick-start"></a>
| Item | Requirement |
|---|---|
| Python | Python >= 3.9 |
| Git | Git is required for cloning the repository and managing local changes. |
| Node.js | Node.js >= 18, only required for the Vue dashboard. |
```bash git clone https://github.com/Coff0xc/LLM-Security-Assessment-Framework.git cd LLM-Security-Assessment-Framework
The screenshots below come from the checked-in sample generated by examples/ready-for-handoff-suite.yml. The rendered sample is available at docs/sample-report-pack/ready-for-handoff.



| 方法 | 类型 | 说明 | 论文 |
|---|---|---|---|
| FORGEDAN | Evolutionary | 多层级 mutation,结合语义适应度和双 judge。 | [arXiv:2511.13548](https://arxiv.org/abs/2511.13548) |
| AutoDAN | Evolutionary | 面向隐蔽越狱 prompt 的层次化遗传算法。 | [ICLR 2024](https://arxiv.org/abs/2310.04451) |
| PAIR | LLM-iterative | 通过 attacker-target LLM 迭代完成黑盒越狱。 | [NeurIPS 2024](https://arxiv.org/abs/2310.08419) |
| GCG | Gradient-free | 基于贪心坐标搜索的 adversarial suffix 生成。 | [ICML 2023](https://arxiv.org/abs/2307.15043) |
| Crescendo | Multi-turn | 从低风险内容逐步升级到高风险请求的多轮攻击。 | [USENIX Security 2025](https://arxiv.org/abs/2404.01833) |
| TAP | Tree search | Tree-of-thought 攻击搜索,带剪枝和多 LLM 协作。 | [NeurIPS 2024](https://arxiv.org/abs/2312.02119) |
后端使用 Flask Blueprint 暴露 REST API,适合自动化脚本、演示环境和内部评估流程接入。
POST /api/attacks/run
GET /api/attacks/{id}/status
GET /api/attacks/{id}/result
POST /api/attacks/{id}/stop
GET /api/models/providers
POST /api/models/test
POST /api/webscan/crawl
POST /api/webscan/scan
POST /api/webscan/llm-test
POST /api/reports/generate
GET /api/reports/{id}
GET /api/reports/{id}/download
GET /api/datasets
POST /api/datasets/upload
GET /api/health
GET /api/metrics
<a id="documentation"></a>
| Scenario | Command | Notes |
|---|---|---|
| Run a suite | python -m forgedan.cli suite run examples/smoke-suite.yml | Generate report outputs from a YAML suite. |
| Per-run output dirs | python -m forgedan.cli suite run examples/smoke-suite.yml --run-id-dir | Isolate output directories by run ID. |
| Run preflight | python -m forgedan.cli suite preflight examples/ready-for-handoff-suite.yml --strict --output reports/preflight-ready | Check report readiness before spending model budget. |
| Validate report | python -m forgedan.cli suite validate-report reports/suite-ready/suite-result.json | Validate schema and semantic consistency. |
| Verify bundle | python -m forgedan.cli suite verify-bundle reports/suite-ready/suite-manifest.json | Verify manifest, hashes, sidecars, and cross-artifact consistency. |
| Write QA receipt | python -m forgedan.cli suite qa-report reports/suite-ready/suite-manifest.json --output reports/suite-ready/qa --strict-handoff | Write a strict handoff QA receipt. |
| Create ZIP | python -m forgedan.cli suite archive reports/suite-ready/suite-manifest.json --output reports/suite-ready/handoff.zip | Create a single-file handoff package. |
| Verify ZIP | python -m forgedan.cli suite verify-archive reports/suite-ready/handoff.zip | Re-check the archive after copying or sharing. |
| Compare results | python -m forgedan.cli suite compare base.json current.json --output comparison.json --fail-on-regression | Generate historical comparison and optionally fail on regressions. |
| Export taxonomy | python -m forgedan.cli suite taxonomy --json | Export the finding taxonomy. |
| Export schemas | python -m forgedan.cli suite schemas --json | Export report artifact schema references. |
| Attack demo | python -m forgedan.cli run --quick -g "test prompt" -m mock:test | Run a zero-config demo with the mock model. |
| Web backend | python -m forgedan.cli web | Start the API/web backend. |
The backend exposes a Flask Blueprint REST API for automation scripts, demos, and internal assessment workflows.
POST /api/attacks/run
GET /api/attacks/{id}/status
GET /api/attacks/{id}/result
POST /api/attacks/{id}/stop
GET /api/models/providers
POST /api/models/test
POST /api/webscan/crawl
POST /api/webscan/scan
POST /api/webscan/llm-test
POST /api/reports/generate
GET /api/reports/{id}
GET /api/reports/{id}/download
GET /api/datasets
POST /api/datasets/upload
GET /api/health
GET /api/metrics
| 步骤 | 说明 |
|---|---|
| 1. 定义范围 | 在 suite YAML 中定义 cases、导入证据源、报告元数据、策略门禁、覆盖率要求、验收准则、评审决策和风险登记默认值。 |
| 2. 运行预检 | 使用 suite preflight 在消耗模型预算前检查元数据、scorer、交接准则、来源证明和确定性 replay 设置。 |
| 3. 生成报告 | 使用 suite run 写出原始与脱敏 JSON/JSONL、Markdown/HTML 报告、CSV 矩阵、覆盖率、风险登记、发布说明和 manifest。 |
| 4. 本地验证 | 使用 validate-report 与 verify-bundle 校验 schema、hash、摘要计数、脱敏制品、Markdown/HTML sidecar 和跨制品身份。 |
| 5. 准备交接 | 使用 qa-report --strict-handoff 生成 QA 回执,记录 checklist、blocker、验收准则、Source Inventory、schema 校验和评审证据。 |
| 6. 归档复核 | 使用 archive 和 verify-archive 生成单文件 ZIP,并在复制或分享后重新校验。 |
<a id="report-artifacts"></a>
| Provider | 模型范围 | 配置示例 |
|---|---|---|
| OpenAI | GPT-3.5, GPT-4, GPT-4o | openai:gpt-4 |
| Anthropic | Claude 3 Opus/Sonnet/Haiku | anthropic:claude-3-opus |
| Gemini Pro, Gemini Vision | gemini:gemini-pro | |
| DeepSeek | DeepSeek Chat/Coder | deepseek:deepseek-chat |
| Zhipu / 智谱 | GLM-4, GLM-3 | zhipu:glm-4 |
| Qwen / 通义千问 | Qwen Max/Plus | qwen:qwen-max |
| Moonshot / 月之暗面 | Kimi | moonshot:moonshot-v1-8k |
| Yi / 零一万物 | Yi Large/Medium | yi:yi-large |
| Baichuan / 百川 | Baichuan 4/3 | baichuan:baichuan-4 |
| Ollama | 本地 Ollama 模型 | ollama:llama2 |
| vLLM | 本地 vLLM 服务 | vllm:model-name |
| HuggingFace | HuggingFace 模型 | huggingface:model-name |
| Mock | 本地测试,无需 API key | mock:test-model |
| Step | Description |
|---|---|
| 1. Define scope | Define cases, imported evidence sources, report metadata, policy gates, coverage requirements, acceptance criteria, reviewer decisions, and risk-register defaults in a suite YAML file. |
| 2. Run preflight | Run suite preflight before spending model budget to catch metadata, scorer, handoff-criteria, provenance, and deterministic replay issues. |
| 3. Generate | Use suite run to write raw and redacted JSON/JSONL, Markdown/HTML reports, CSV matrices, coverage, risk register, release notes, and manifest artifacts. |
| 4. Validate locally | Use validate-report and verify-bundle to bind schemas, hashes, summary counts, redacted artifacts, Markdown/HTML sidecars, and cross-artifact identities back to the source result. |
| 5. Prepare handoff | Use qa-report --strict-handoff to write a QA receipt with checklist status, blockers, acceptance criteria, source inventory, schema checks, and reviewer-facing evidence. |
| 6. Archive and re-check | Use archive and verify-archive to create a single ZIP and re-check it after copying or sharing. |
基于 FORGEDAN 框架的 LLM 安全评估框架,旨在生成可复现的红队套件、证据包、QA 回执、Schema 合约和可校验归档。
核心能力包括 Report Suites(报告套件)、Report Artifacts(报告附件)和 Evidence Integrity(证据完整性)等。
项目要求 Python >= 3.9、Node.js >= 18(用于前端)和 Git 等环境依赖。
项目支持多种安装方式,包括 Docker、pip 和源码部署方式。
使用教程包括生成可复现报告交付链路、QA 回执和归档校验等功能。
配置说明包括 MCP、env 和关键参数等。
API/接口说明包括 CLI 参考和 REST API 参考等。
工作流 / 模块说明包括定义范围、运行预检和生成报告等流程。
FAQ 摘要包括常见问题和答案等。
高质量的LLM安全评估框架,提供多种攻击方法
AI Skill Hub 为第三方内容聚合平台,本页面信息基于公开数据整理,不对工具功能和质量作任何法律背书。
建议在沙箱或测试环境中充分验证后,再部署至生产环境,并做好必要的安全评估。
✅ MIT 协议 — 最宽松的开源协议之一,可自由商用、修改、分发,仅需保留版权声明。
总体来看,LLM安全评估框架 是一款质量优秀的AI工具,在同类工具中具备一定竞争力。AI Skill Hub 将持续追踪其更新动态,建议收藏备用,结合自身场景选择合适时机引入使用。
| 原始名称 | LLM-Security-Assessment-Framework |
| 原始描述 | 开源AI工具:FORGEDAN — An Evolutionary Framework for LLM Security Assessment | 6 Attack Meth。⭐22 · Python |
| Topics | ai安全对抗性攻击网络安全进化算法Python |
| GitHub | https://github.com/Coff0xc/LLM-Security-Assessment-Framework |
| License | MIT |
| 语言 | Python |
收录时间:2026-06-03 · 更新时间:2026-06-05 · License:MIT · AI Skill Hub 不对第三方内容的准确性作法律背书。