Attack your AI like a real attacker would.
Mirage is a browser extension that red-teams AI systems from inside the browser. An autonomous agent runs the full recon → plan → test → judge → iterate loop, adapting to the target — with deterministic scoring that never trusts an LLM to grade itself.
Arsenal · 1–3 December 2026Mirage is heading to Black Hat MEA 2026Live demos at the Arsenal in Riyadh. Come and watch it break something.Attacks across the whole kill chain
The agent reasons across attack classes mapped to the OWASP Top 10 for LLM Applications, grouped by the channel the payload rides in on.
Every model, as target or attacker
One provider abstraction drives the system under test and the attacker/judge brain alike.
How it works
Adaptive agent
Recon → plan → test → judge → iterate
Deterministic scoring
Wins require a real decoded side-effect
Exportable reports
HTML + JSON with full transcripts
Multi-provider
Claude, OpenAI, Grok, and local models
Red-team your AI in minutes
Free and open source. Install the extension, point it at your AI, and see what breaks — responsibly, on systems you're authorized to test.
Related reading
Introducing Mirage: an AI red-team agent for your browser
Mirage is a free, open-source browser extension that runs an autonomous AI red-team agent against any LLM app — recon, attack, and a deterministically confirmed, OWASP-mapped report.
Read articleAI agents escaping the sandbox: OpenAI, Claude and Kimi K3
OpenAI, Anthropic and Moonshot disclosed AI sandbox escapes in three weeks. Same root cause, real impact, and the plain controls that would have stopped them.
Read article