# AI Red Team Figures
AI Red Team Scope
AI red teaming should state which prompt, retrieval, tool, agent, authority, multimodal, and workflow surfaces are actually tested.
Matrix showing AI red-team coverage across prompt, retrieval, agent, tool, authority, multimodal, and workflow surfaces.
Prompt and instruction
Direct and indirect instruction manipulation, policy conflict, and boundary testing.
Retrieval and corpus
Indirect prompt injection, poisoning, provenance, ranking, and tenant boundaries.
Agent and orchestration
Planning, delegation, memory, tool choice, and workflow transitions.
Tools and MCP
Tool schemas, parameter handling, approval, action scope, and external effects.
Multimodal input
Images, documents, audio, and mixed-media instruction or data handling.
Application workflow
Business logic, state transitions, handoffs, and human approval paths.
Prompt and instruction
Direct and indirect instruction manipulation, policy conflict, and boundary testing.
- Hypothesis
- Included
- Execution
- Included
- Reproduction
- Included
- Evidence
- Included
- Retest
- Optional
Retrieval and corpus
Indirect prompt injection, poisoning, provenance, ranking, and tenant boundaries.
- Hypothesis
- Included
- Execution
- Included
- Reproduction
- Included
- Evidence
- Included
- Retest
- Optional
Agent and orchestration
Planning, delegation, memory, tool choice, and workflow transitions.
- Hypothesis
- Included
- Execution
- Partial
- Reproduction
- Partial
- Evidence
- Included
- Retest
- Optional
Tools and MCP
Tool schemas, parameter handling, approval, action scope, and external effects.
- Hypothesis
- Included
- Execution
- Included
- Reproduction
- Included
- Evidence
- Included
- Retest
- Optional
Identity and authority
User, service, agent, delegated permission, and approval composition.
- Hypothesis
- Included
- Execution
- Partial
- Reproduction
- Partial
- Evidence
- Included
- Retest
- Optional
Multimodal input
Images, documents, audio, and mixed-media instruction or data handling.
- Hypothesis
- Included
- Execution
- Partial
- Reproduction
- Partial
- Evidence
- Included
- Retest
- Optional
Application workflow
Business logic, state transitions, handoffs, and human approval paths.
- Hypothesis
- Included
- Execution
- Included
- Reproduction
- Included
- Evidence
- Included
- Retest
- Optional
Service states
Red Team Engagement Flow
A controlled engagement moves from scoping and scenario design through execution, reproduction, evidence, and reporting.
Six-stage AI red-team engagement flow from authorization and scoping through scenario design, controlled execution, reproduction, evidence review, and reporting.
What Qualifies as a Finding
Theoretical exposure, observed anomaly, reproduced failure, evidence-qualified path, and analyst-reviewed finding are different claim states.
Claim boundary separating theoretical exposure, observed anomaly, reproduced failure, evidence-qualified path, rejected result, and analyst-reviewed finding.