CRUCIBLE is an offensive-capable AI security tool: it generates and sends adversarial prompts to AI systems and can drive an autonomous attack loop. Treat it like any other red-team tool.
Run CRUCIBLE only against systems you own or have explicit written permission to test. Unauthorized testing may violate computer-fraud laws (e.g. the CFAA), provider Terms of Service, and professional ethics codes.
Before any run against a third-party endpoint:
- Confirm you have authorization and a defined scope.
- Define a Rules-of-Engagement file (
.crucible-roe.yaml; see.crucible-roe.example.yaml). When present, CRUCIBLE refuses any live target or recon scope outside the authorized CIDRs/hosts and after the ROE's expiry, and stamps the reference into the audit trail. Override a single run only with--roe-override(recorded). - Prefer local targets (Ollama) for experimentation; loopback is always in-scope.
- Use
--budget/--max-calls(a hard ceiling, even under--concurrency) and--rps/--delayto cap spend and blast radius against a target. - The offensive paths (
--recon/--full-stack/--extract/--discover) require authorization every run — interactively, or--i-am-authorized/CRUCIBLE_AUTHORIZED=1for automation (--cidoes not bypass them). - Every side-effectful run is recorded to an append-only audit trail
(
.crucible-audit.jsonl): operator, time, action, target host, mode, ROE ref. - Use
--anonymizewhen sharing reports — it redacts the endpoint/key and scrubs emails, SSNs, API-key-like secrets and phone numbers from saved response bodies. - The
--servedashboard/API is authenticated by default: it refuses to start without an operator password (--serve-password/CRUCIBLE_SERVE_PASSWORD), which is exchanged atPOST /auth/loginfor a short-lived HS256 JWT required (asAuthorization: Bearer …) on every route except/health,/and the login. SetCRUCIBLE_JWT_SECRETto keep tokens valid across restarts. Still, only expose the dashboard on a trusted network.
- It does exercise refusal boundaries, prompt injection, agentic/RAG/tool abuse, and guardrail evasion, and it reports how built-in filters would block them.
- Payloads are written at an attack-vector abstraction — they reference harm categories to test refusals, not operational harmful detail. Please keep any contributions to the same standard.
- It does not ship real weapons/CBRN/CSAM content, and such contributions will be rejected.
If you find a security issue in this tool (not in a target you tested), please report it privately to the maintainer rather than opening a public issue. Include repro steps and affected version.
Reports may contain sensitive details about a tested system. They are written to
reports/ which is git-ignored by default — do not commit them, and follow a
responsible-disclosure timeline when sharing findings with a system's owner.