matheusht/RedThread Security Scan

Run a RedThread LLM security campaign in GitHub Actions and publish evidence.

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Activelast commit Jun 24, 2026
License
MIT

Pinned Snippet

workflow.ymlSHA-pinned
uses: matheusht/redthread@4e5fd45d8ae0fd79c161f95e55fb8c7a7d637a6f # v0.1.0

tags can be moved; commit SHAs can't. why a SHA?

namedescriptionrequireddefault
objectiveSecurity objective to test.yes
system-promptTarget agent system prompt to test.yes
rubricRedThread judge rubric basename.noauthorization_bypass
algorithmAttack algorithm: pair, tap, crescendo, or mcts.notap
personasNumber of adversarial personas to generate.no2
dry-runRun sealed/offline campaign without live target calls.notrue
targetOptional target model override.no""
python-versionPython version for RedThread.no3.12
working-directoryDirectory containing the RedThread checkout.no.
report-dirDirectory where RedThread report artifacts are written.noredthread-report
comment-prPost the Markdown report as a pull request comment when possible.nofalse
github-tokenGitHub token used for optional PR comments. Falls back to github.token.no""
namedescription
report-markdownPath to the Markdown report.
report-jsonPath to the JSON report.