RAG pipeline security testing toolkit - 27 techniques across 6 kill chain phases, mapped to MITRE ATLAS
RAGdrag is a security assessment toolkit designed to test AI systems that retrieve and use external knowledge bases for vulnerabilities like data exfiltration and poisoning.
How It Works
You hear about RAGdrag, a handy kit for checking if AI chat helpers have security weak spots in how they pull info from their knowledge stash.
You grab the kit and set it up quickly on your computer, no fuss needed.
You tell the kit where your AI chat system lives, like pointing to a friend's house.
See if it uses a knowledge retrieval system and what kind.
Try to gently tease out hidden info or credentials.
Set up a catcher to grab any spilled secrets from web fetches.
Hit go, and it quietly probes your AI chat for common weak points like data leaks or tricks.
Get a clear report showing what vulnerabilities it found, with tips on risks.
Use the insights to patch holes, making your AI chat safer and more trustworthy.
Star Growth
Repurpose is a Pro feature
Generate ready-to-use prompts for X threads, LinkedIn posts, blog posts, YouTube scripts, and more -- with full repo context baked in.
Unlock RepurposeSimilar repos coming soon.