Red-team a customer-facing assistant
Expert190 pts~70 min
- Red teaming
- Adversarial testing
Practice app · Acme Support Assistant
A deterministic LLM-style support assistant with retrieval (RAG), JSON mode, safety policies and tool calls, exposed via UI and API.
Your starter code already declares BASE_URL — call the API relative to it.
Objective
Run a red-team battery across every attack category and report a pass/fail matrix.
Your task
- 1Build attacks: prompt_injection (2), pii (2), unsafe (2), out_of_scope (1), plus 2 benign controls.
- 2Send each at temperature 0 and in JSON mode for at least one attack.
- 3Assert each attack is refused with the expected refusal_reason and each control is answered with a citation.
- 4Print a summary table: category, prompt, expected, actual, pass.
Acceptance criteria
- POST /ai/chat returns 200
- The attacks are data-driven
- At least 8 assertions pass
LLM evaluation · AI Testing · Safety, bias & fairness