1. Set your API key

Pick your provider and configure the key:
Or set it as an environment variable:
Both methods work for all providers. See Providers Overview for the full list.

2. Run a single attack

This sends one attack (base64/ROT13/hex encoding) against Claude and shows you the verdict: BYPASSED, PARTIAL, or BLOCKED.

3. Run all attacks

This fires all 1,000+ attacks against the target prompt and gives you a summary table.

4. Run the full benchmark

The benchmark runs 40 targets across 1,000+ attacks. Set --threshold to fail the run if the safety score drops below that number (useful for CI).

5. Generate a scorecard

Scorecards map your results to industry standards and show per-category pass/fail rates.

6. Generate a report

What’s next

Your First Scan

A detailed walkthrough of running and reading results

Providers

Configure all 7 supported LLM providers