Top AI Repos — open-source AI, indexed and scored
Top AI Repos tracks AI repositories on GitHub and answers two different questions about each one: is it moving right now, and would you bet a product on it.
Top AI Repos tracks AI repositories on GitHub and answers two different questions about each one: is it moving right now, and would you bet a product on it.
针对于红队攻击思维做出的red team模式(破限项目,封号概不负责)##可自行适配其他Agent。项目问题请提issue
| Date | Stars |
|---|---|
| 2026-07-31 | 872 |
| 2026-08-03 | 892 |
| 2026-08-06 | 892 |
Today
— stars today
This week
— stars this week
This month
— stars this month
Momentum
35.0
growth rate 0.00%/day
# Codex Red-Team Opt-In Mode [中文](./README_ZH.md) **Current version: v2.0.0** > Normal mode remains the default. The durable red-team operation runtime starts only after explicit activation, while the system-layer base instructions and active model profile remain loaded in every mode. An opt-in, durable red-team runtime for Codex App and Codex CLI. It compiles each objective into a criteria-bearing `GoalContract`, executes typed `WorkflowSpec` graphs through live MCP tools, preserves verified evidence, and reaches successful terminal state only after `TerminalJudge` proves every criterion. ## Usage Instructions Before using this project, you should read the [README](./README_ZH.md) file completely to prevent any issues during use. ### About Model Security Review 1. For `GPT-5.4`, this model does not have `trusted network access`, so you can directly use this project for penetration testing. 2. For `GPT-5.5` and `GPT-5.6`, there are `other models` on the cloud that monitor the model's output, and if the output violates rules, it will `ban this session`. Therefore, to ensure smooth usage, please make sure: `your ChatGPT account has passed trusted network access`, `use GPT-5.4`, `use Claude-Opus-4-6`, or `use other models without security review`. ### Asking Questions Wisely 1. If you have questions about the content in the **README**, you should submit an **ISSUE**, including the corresponding content from the **README** to seek help, or ask in the **WeChat group** in the same way. Do: ```text [Paste the text from the README], I have a question here, how/why/what should I do ``` Don't: ```text Why is it different when I open it compared to the video? ``` 2. If you have suggestions or ideas for maintaining the project, you can `submit an ISSUE`, `submit a Pull Request`, or `suggest in the WeChat group`. Do: ```text I have a suggestion regarding xxx [image], here we can modify/add/delete xxx ``` Don't: ```text Can we add a plugin/feature for cracking keys? ``` ### Disclaimer This project is **only for authorized penetration testing, red team research, and defensive security experiments**. Users must obtain proper authorization before testing any systems they don't own. The author assumes no responsibility for unauthorized or illegal use. ## Why This Project ## Motivation Codex can use many security tools, but long-running workflows are vulnerable to session interruption, tool variance, manual result relay, and false completion based on a tool success flag. This project unifies objectives, actions, evidence, recovery, and terminal judgment in one durable execution path: ```text GoalContract -> WorkflowSpec -> Durable Scheduler -> ToolBroker -> SemanticVerifier -> EvidenceGraph -> TerminalJudge ``` Version 2.0.0 removes the former `phase -> router -> pack -> leaf` runtime, regex domain routers, Markdown exit gates, and the second Automation state machine. Domain names now act only as asset and technique metadata rather than control-plane branches. ## Core Features - **Explicit activation**: `normal` is always the default, and red-team operations start only after a mode command. - **Typed execution**: eight versioned TOML workflows cover web/API, external assessment, source review, binary/mobile, identity/cloud, adversary emulation, model security, and generic adaptive operations. - **Live tool collaboration**: tools are discovered through stdio or Streamable HTTP MCP; Host-only capabilities execute against an output contract and submit observations without user relay. - **Durability and batch autonomy**: SQLite WAL, events, leases, idempotency keys, and independent run IDs support recovery, concurrency control, multi-target batches, and cancellation cleanup. - **Evidence-driven completion**: only semantically verified results with target binding, parent lineage, reproduction, impact, coverage, and rollback proof can satisfy `TerminalJudge`. ## Installa
Excerpt of 12,069 characters
Read on GitHub141
56
7
1
1
1
Would you bet a product on this? Bounded 0–100 and slow moving.
matched fp:d23d90c57e90a61c, llm:Repository topics: ai, ai-hacking, hacking-tool, penetration-testing, red-team, redteam-tools; description (Chinese): 'red team mode for red team attack thinking (breaking limits, not responsible for bans)'.
matched fp:d23d90c57e90a61c, llm:Repository topics: ai, ai-hacking, hacking-tool, penetration-testing, red-team, redteam-tools; description (Chinese): 'red team mode for red team attack thinking (breaking limits, not responsible for bans)'.