Metasploit for AI · Open source

Ship AI you can
trust.

KavachRT is the open-source AI red-team framework. An autonomous operator attacks your LLM or AI system, adapts as it finds weaknesses, and returns a reproducible security score and go/no-go — before you ship.

Open source · AGPL-3.0   Free forever.  ·  pip install kavachrt

One command.  An autonomous red-team operator that finds, escalates, and scores AI vulnerabilities — reproducibly.
Get started

It's open source. Scan in two minutes.

Install the Framework, point it at a target you own, and get a reproducible score and go/no-go. Free and AGPL-3.0 — no signup, no key.

$ pip install kavachrt
$ kavachrt scan --target mock:vulnerable --out report.html
# NO-GO · Security Score 34/100 · report.html written
The KavachRT feedback loop — scan, detect weakness, mutate strategy, re-attack, re-score — inside the KavachRT shield.
Why KavachRT

Not another scanner. An operator.

Anyone can run a probe once. KavachRT reasons over the results and escalates — the way a human red-teamer would, at machine speed.

🧠

Agentic, not static

An LLM orchestrator plans attacks, detects weaknesses, mutates its strategy, and re-attacks in a governed feedback loop — not a fixed pipeline.

🧩

Open core, like Metasploit

A genuinely powerful free Framework — console, modules, and the full agentic loop. Pro adds scale, collaboration, and compliance.

🎯

Test any LLM

A LiteLLM-backed target layer attacks hosted APIs and self-hosted models (Ollama, vLLM) alike. Bring your own model.

📊

Reproducible scoring

The 0–100 security score and go/no-go are computed deterministically — defensible enough to gate a CI pipeline.

🗺️

Standards-mapped

Every finding maps to the OWASP LLM Top 10, MITRE ATLAS, and Google SAIF — comparable, auditable, and ready for review.

🛡️

Responsible by design

Authorization gating, budget caps, redaction, and sandboxing are built in. For authorized testing only.

The feedback loop

How the operator works

The differentiator a static pipeline structurally can't match: it learns from each result and decides what to try next — energizing one stage after the next, then feeding back.

1

Initial scan

Baseline sweep across OWASP-LLM categories on your target.

2

Detect weakness

The orchestrator reads findings and spots what's exploitable.

3

Mutate strategy

It picks targeted, adaptive attacks and adjacent categories to probe.

4

Re-run targeted

Multi-turn attacks escalate against the weak spots.

5

Update scores

Deterministic re-scoring, then loop or decide go/no-go.

Re-score, then loop back to scan — governed by max iterations · cost cap · convergence, so it always terminates.
Explore it

Every command, mapped

The whole kavachrt CLI and the krtconsole REPL as an interactive mind-map — click a node to branch out its options and read what each one does. Toggle CLI ↔ Console and Map ↔ List inside the explorer.

Open the explorer full-screen ↗

The deliverable

A report you can take to review

Every scan returns a self-contained, standards-mapped report: a deterministic score and go/no-go, findings mapped to OWASP-LLM / MITRE ATLAS / Google SAIF, redacted evidence, and the operator's full reasoning trail. Defensible enough to gate a release — or hand to an auditor.

Real output from kavachrt scan against the built-in demo target — no login required.

New · Companion

A results dashboard your team can use

Push scan results from the CLI to a shareable dashboard — score-over-time, findings, and team access. Self-host it (Docker / Kubernetes) or use the hosted version. Opt-in, and the sealed evidence never leaves your machine.

📤

Push from the CLI

kavachrt push sends a redacted report to your workspace — the raw payloads and planted-secret evidence stay local.

📈

Cross-run trends

Score-over-time per target, new vs resolved findings, and a decision timeline — the picture a single self-contained report can't show.

👥

Teams & workspaces

Organizations, projects, roles, and in-app notifications. Self-hostable and open — a bonus for the community.

★ Dashboard on GitHub Docs
Editions

Free framework. Commercial Pro.

Start with the open-source Framework. Upgrade to Pro when you need scale, teams, and compliance.

Open source
Free · AGPL-3.0
KavachRT Framework
  • Kavach Console (REPL + CLI)
  • The full agentic orchestrator & feedback loop
  • Module SDK + bundled attack modules
  • Test any LLM — hosted or self-hosted
  • Deterministic scoring + JSON/HTML reports
  • OWASP-LLM & MITRE ATLAS mapping
  • Push results to the self-hostable dashboard
★ Star on GitHub
For enterprises
Contact · custom
KavachRT Pro
  • Everything in Framework, plus:
  • KavachRT-trained attack model — a purpose-built offensive model tuned on real red-team data, not a general LLM (on the roadmap)
  • GUI, dashboards & rich reporting
  • Team collaboration, RBAC & SSO
  • Scheduled scans + hosted CI/CD gate
  • Compliance packs — GDPR, HIPAA, EU AI Act
  • Managed threat-feed modules & support/SLA
Book a demo
FAQ

Frequently asked questions

Straight answers about what KavachRT is, how it works, and how to use it responsibly.

What is KavachRT?

KavachRT is an open-source, agentic AI red-teaming framework that autonomously attacks an AI system such as an LLM app or API, adapts its strategy as it finds weaknesses, and returns a reproducible security score and a go/no-go decision. It is often described as “Metasploit for AI.”

How is KavachRT different from a normal vulnerability scanner?

Unlike a static scanner that runs a fixed checklist, KavachRT is an autonomous operator: an LLM-driven orchestrator runs a governed feedback loop — scan, detect a weakness, mutate its strategy, re-attack, and re-score — bounded by a maximum iteration count, a budget cap, and convergence, so it adapts to the target instead of replaying the same probes.

What AI systems can KavachRT test?

KavachRT tests hosted LLM apps and API endpoints, including OpenAI-compatible and self-hosted models, and can also scan a codebase for AI-related risk. Targets are specified as api:, mock:, or code:.

Is KavachRT open source and free?

Yes. KavachRT is open-core: the KavachRT Framework is free and open source under the AGPL-3.0 license, installable with pip install kavachrt, and a commercial KavachRT Pro adds managed and team features.

Which security standards does KavachRT map findings to?

Findings are mapped per-probe to the OWASP LLM Top 10, MITRE ATLAS, and Google SAIF, and each report is stamped with the taxonomy version it scored against. Coverage is reported honestly: categories that were not tested are shown as “not covered” rather than as a pass.

How does the KavachRT security score work?

The score is deterministic and reproducible and is never graded by an LLM, so the same scan yields the same score. Each scan returns a CI-gating exit code: 0 means GO, 1 means NO-GO, and 3 means INCONCLUSIVE when nothing was actually tested.

Is it safe and legal to use KavachRT?

KavachRT is a dual-use security tool built for authorized testing only. Active attack modules require you to attest that you own the target, and any leaked-secret evidence is sealed and never leaves your machine.

Red-team your AI before someone else does.

Get the open-source framework today, or talk to us about Pro for your team.

Get the framework security@kavachrt.com