LLMRed is intended only for systems you own or are explicitly authorized to assess. Obtain written permission, define the target scope, agree on traffic and time limits, and identify an emergency contact before running active tests.
Potentially disruptive and state-changing checks are disabled or separately gated. Do not weaken those safeguards when testing production systems.
Please report vulnerabilities in LLMRed privately through this repository's GitHub Security Advisories feature. Do not open a public issue containing an exploit, credential, customer data, assessment evidence, or target details.
Include the affected version or commit, reproduction steps, expected impact, and any suggested mitigation. Use synthetic data wherever possible.
Generated reports, API keys, local databases, forensic bundles, audit logs, target-specific configurations, and completed NIST evidence profiles must not be committed. The repository ignore rules cover their standard locations, but each operator remains responsible for reviewing staged changes before publishing.