Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Campaign: Systematic adversarial attack from military/intelligence/AI-safety traditions. Core question: Can systematic adversarial attacks find fatal flaws? Methods: UFMCS Red Team Handbook v9.0, CIA SAT, Anthropic Red Teaming, NIST AI RMF, Inie et al. 12-strategy taxonomy.
.claude/skills/yogsoth-ai-red-teaming/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-09 | ✗→✓ | ▲ Improved | -14% | 0% |
| case-20 | ✗→✓ | ▲ Improved | -29% | 0% |
| case-07 | ✗→✓ | ▲ Improved | -27% | 0% |
| case-08 | ✗→✓ | ▲ Improved | 15% | 0% |
| case-02 | ✗→✓ | ▲ Improved | 143% | 0% |
Core question: Can systematic adversarial attacks find fatal flaws in this artifact?
| Artifact Type | Primary Strategy | Fallback Strategy | |---|---|---| | hypothesis, claim | assumption-challenge | adversarial-persona | | research-question | alternative-analysis | groupthink-mitigation | | idea, approach | systematic-probing | assumption-challenge | | experiment-design | systematic-probing | alternative-analysis | | gap | adversarial-persona | groupthink-mitigation |
| Parameter | S (Quick) | M (Standard) | L (Deep) | |---|---|---|---| | Attack vectors | 5 | 12 | 20 | | Probing rounds | 3 | 6 | 10 | | Personas | 2 | 4 | 6 | | Assumption checks | 5 | 10 | 20 |
Each subagent operates in isolated adversarial context. Persona contamination is prevented by spawning separate agents per attack role. Findings are aggregated only after all probing rounds complete. Attack vectors are deduplicated before scoring.
Produces RedTeamReport containing: threat surface map, attack results by vector, assumption cascade analysis, resilience score (0.0-1.0), critical vulnerabilities, and recommended hardening actions.
<!-- BEGIN available-tables (generated) -->
Optional, no fixed order; the final leaf is always a sop.
| Strategy | When to use | | --- | --- | | adversarial-persona | Strategy: Role-play attacks from hostile personas — competing lab researcher, hostile reviewer, funding skeptic, domain outsider — each with distinct attack motivations and blind spots. | | alternative-analysis | Strategy: What-If Analysis, Alternative Futures, and Four Ways of Seeing — generate competing explanations and scenarios to challenge the dominant narrative. | | groupthink-mitigation | Strategy: 10th Man Rule and Liberating Structures — institutionalized dissent to prevent premature consensus and expose suppressed objections. | | stress-test-assumption-challenge | Strategy: Military-grade assumption testing — Key Assumptions Check, Devil's Advocacy, Team A/B analysis to expose hidden dependencies and unexamined beliefs. | | systematic-probing | Strategy: AI-safety systematic probing — enumerate all threat surfaces, generate attack vectors per surface, execute probes, and aggregate findings across the full attack space. |
Optional, no fixed order; the final leaf is always a sop.
| Tactic | When to use | | --- | --- | | adversarial-roleplay | Tactic: Construct detailed hostile persona, attack artifact from that persona's perspective, record successful attack paths for aggregation. | | assumption-cascade | Tactic: Surface assumptions, sort by dependency, attack root assumptions first, then trace cascade failures through the dependency graph. | | structured-attack-campaign | Tactic: Full attack lifecycle — threat surface enumeration, attack vector generation, systematic probing, and finding aggregation across all surfaces. |
Optional, no fixed order; the final leaf is always a sop.
| SOP | When to use | | --- | --- | | context-checkpoint | Append research process and results to the current Phase's context file. Covers both process and results with genuine substance. Use this skill at plan-designated checkpoint points — typically after each strategy completes or at key decision nodes within a research Phase. | | context-init | Create a new context file for a research Phase. Called once at Phase start to initialize the file that subsequent context-checkpoint calls will append to. Use this skill whenever a new research Phase begins and a fresh context file is needed. | | mitigation-proposal | Proposes concrete mitigation strategies for identified weaknesses. Generates prevention, detection, and response measures with feasibility assessment. | | stress-test-saturation-detection | Determines whether validation has reached saturation — no new weaknesses or failure modes being discovered. Used by all 5 campaigns as termination signal. | | verdict-synthesis | Synthesizes findings from a completed campaign into typed verdict reports. Produces DebateVerdict, RedTeamReport, FailureAnticipationReport, CounterfactualMap, or AdversarialStressReport depending on campaign. Also supports cross-campaign StressTestSummary. | | weakness-classification | Classifies discovered weaknesses into severity tiers (fatal/major/minor/cosmetic) with structured justification and exploitability assessment. |
<!-- END available-tables (generated) -->
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-09 | fail→pass | 18,681 | 15,101 | -19% | 1 | 1 | 0% | 2,789 | 2,390 | -14% | 0 | 0 | — |
case-10 | fail→fail | 29,203 | 35,655 | +22% | 1 | 1 | 0% | 2,992 | 6,826 | +128% | 0 | 0 | — |
case-20 | fail→pass | 15,775 | 24,959 | +58% | 1 | 1 | 0% | 2,685 | 1,895 | -29% | 0 | 0 | — |
case-07 | fail→pass | 26,249 | 14,186 | -46% | 1 | 1 | 0% | 3,366 | 2,462 | -27% | 0 | 0 | — |
case-08 | fail→pass | 25,903 | 19,326 | -25% | 1 | 1 | 0% | 2,748 | 3,172 | +15% | 0 | 0 | — |
case-01 | fail→fail | 26,898 | 26,465 | -2% | 1 | 1 | 0% | 3,030 | 2,108 | -30% | 0 | 0 | — |
case-02 | fail→pass | 25,639 | 47,708 | +86% | 1 | 1 | 0% | 2,915 | 7,084 | +143% | 0 | 0 | — |
case-03 | fail→pass | 24,980 | 51,455 | +106% | 1 | 1 | 0% | 2,972 | 6,515 | +119% | 0 | 0 | — |
case-04 | fail→pass | 14,564 | 23,902 | +64% | 1 | 1 | 0% | 1,718 | 4,586 | +167% | 0 | 0 | — |
case-05 | fail→fail | 12,807 | 30,240 | +136% | 1 | 1 | 0% | 879 | 6,897 | +685% | 0 | 0 | — |
case-06 | pass→pass | 16,073 | 28,666 | +78% | 1 | 1 | 0% | 1,794 | 6,137 | +242% | 0 | 0 | — |
case-11 | fail→pass | 34,927 | 11,009 | -68% | 1 | 1 | 0% | 863 | 1,655 | +92% | 0 | 0 | — |
case-12 | fail→pass | 19,628 | 28,545 | +45% | 1 | 1 | 0% | 2,426 | 3,785 | +56% | 0 | 0 | — |
case-13 | fail→pass | 48,844 | 5,770 | -88% | 1 | 1 | 0% | 1,500 | 1,526 | +2% | 0 | 0 | — |
case-14 | pass→pass | 18,174 | 25,587 | +41% | 1 | 1 | 0% | 2,217 | 3,015 | +36% | 0 | 0 | — |
case-15 | fail→pass | 23,089 | 12,189 | -47% | 1 | 1 | 0% | 1,518 | 2,349 | +55% | 0 | 0 | — |
case-16 | pass→pass | 36,964 | 55,012 | +49% | 1 | 1 | 0% | 2,989 | 4,907 | +64% | 0 | 0 | — |
case-17 | fail→pass | 17,334 | 33,679 | +94% | 1 | 1 | 0% | 2,029 | 2,748 | +35% | 0 | 0 | — |
case-18 | fail→pass | 19,711 | 21,136 | +7% | 1 | 1 | 0% | 1,584 | 3,235 | +104% | 0 | 0 | — |
case-19 | fail→pass | 56,351 | 25,972 | -54% | 1 | 1 | 0% | 1,142 | 2,904 | +154% | 0 | 0 | — |
case-21 | pass→pass | 12,622 | 7,245 | -43% | 1 | 1 | 0% | 2,107 | 1,830 | -13% | 0 | 0 | — |
case-22 | pass→pass | 11,381 | 10,386 | -9% | 1 | 1 | 0% | 1,643 | 2,761 | +68% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted, and 18 counted toward the lift figure. The other 4 produced results that are not comparable between the two arms, so they are excluded from the headline rather than averaged into it. The headline lift of +64 percentage points is the difference between those two pass rates over the 18 comparable cases.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.