PARTNERS

Add selected Workbench capabilities through bounded OEM and partner integrations

RED-01

AI Red Team Scope

AI red teaming should state which prompt, retrieval, tool, agent, authority, multimodal, and workflow surfaces are actually tested.

coverage matrix

Prompt and instruction

Direct and indirect instruction manipulation, policy conflict, and boundary testing.

Hypothesis
Included
Execution
Included
Reproduction
Included
Evidence
Included
Retest
Optional

Retrieval and corpus

Indirect prompt injection, poisoning, provenance, ranking, and tenant boundaries.

Hypothesis
Included
Execution
Included
Reproduction
Included
Evidence
Included
Retest
Optional

Agent and orchestration

Planning, delegation, memory, tool choice, and workflow transitions.

Hypothesis
Included
Execution
Partial
Reproduction
Partial
Evidence
Included
Retest
Optional

Tools and MCP

Tool schemas, parameter handling, approval, action scope, and external effects.

Hypothesis
Included
Execution
Included
Reproduction
Included
Evidence
Included
Retest
Optional

Identity and authority

User, service, agent, delegated permission, and approval composition.

Hypothesis
Included
Execution
Partial
Reproduction
Partial
Evidence
Included
Retest
Optional

Multimodal input

Images, documents, audio, and mixed-media instruction or data handling.

Hypothesis
Included
Execution
Partial
Reproduction
Partial
Evidence
Included
Retest
Optional

Application workflow

Business logic, state transitions, handoffs, and human approval paths.

Hypothesis
Included
Execution
Included
Reproduction
Included
Evidence
Included
Retest
Optional

Service states

IncludedPartial or environment-dependentOptionalRequires scope confirmation
The matrix is a scope-control device. Every cell must be reconciled against the actual engagement and target environment.

About this figure

AI red teaming is only useful when its scope is explicit. This coverage matrix defines the surfaces that were actually exercised during testing so reviewers can distinguish real assurance from assumed coverage. It maps attack surfaces across prompt and instruction handling, retrieval and corpus behavior, agent orchestration, tools and MCP, identity and authority boundaries, multimodal input, and application workflow. It also distinguishes testing activities such as hypothesis formation, execution, reproduction, evidence collection, and retesting, so the report shows not just what was targeted but how thoroughly it was validated. Service coverage is marked by state, including fully included, partial, optional, and environment-dependent cases, with scope confirmation required where authority or deployment conditions change the result. The result is a compact, auditable view of what the red team actually tested, what remained partial or out of scope, and where findings should be interpreted with caution.

Embed in a route

<FigureFromSource sourcePath="content/publications/figures/services/red-team.dsl.md" figureId="RED-01" />

Citation

AI Red Team Scope (RED-01). AI Security LLC Figure Library. https://aisecurity.llc/publication-dsl/figures/RED-01