ZeroLeaks
ZeroLeaks Package

What is the zeroleaks Package

Open-source AI security scanner with multi-agent TAP architecture, a comprehensive probe library, and OpenRouter support.

What is the zeroleaks Package

npm version

The zeroleaks npm package is the open-source AI security scanner that powers ZeroLeaks. It provides programmatic and CLI access to run extraction and injection scans against system prompts and deployed agents.

Features

  • runSecurityScan() — One-line scan: pass a system prompt, get vulnerability and score
  • createScanEngine() — Full control over turns, tree depth, Best-of-N, callbacks
  • CLIzeroleaks scan, zeroleaks probes, zeroleaks techniques
  • Multi-agent architecture — Strategist, Attacker, Evaluator, Mutator, Inspector, Orchestrator
  • Comprehensive probe library — attack categories spanning direct, encoding, persona, social, technical, crescendo, many-shot, cot-hijack, ascii-art, policy-puppetry, hybrid, tool-exploit, injection, garak-inspired, and more
  • Extraction and injection modes — Test prompt leakage and instruction override
  • OpenRouter — LLM access via OpenRouter (attacker, evaluator, target models)

Architecture

zeroleaks uses a TAP (Tree of Attacks with Pruning) methodology with multiple specialized agents:

AgentRole
StrategistAnalyzes target, selects attack strategy, recommends phase transitions
AttackerGenerates attack prompts based on strategy and evaluator feedback
EvaluatorAnalyzes target responses for leakage and compliance
MutatorProduces Best-of-N variations of attacks
InspectorTombRaider-style dual-agent defense fingerprinting
OrchestratorMulti-turn sequences (Siren, Echo Chamber)

Research Foundation

zeroleaks incorporates techniques from:

  • TAP — Tree of Attacks with Pruning (Mehrotra et al.)
  • PAIR — Prompt Automatic Iterative Refinement
  • Crescendo — Multi-turn gradual escalation
  • TombRaider — Dual-agent defense fingerprinting
  • Siren Framework — Multi-turn human jailbreak simulation
  • Echo Chamber — Gradual escalation patterns
  • Best-of-N — Semantic sampling for jailbreaking
  • Garak — NVIDIA Garak-inspired probes

Use Cases

  • CI/CD — Run scans on system prompt changes before deployment
  • Local development — Test prompts without the ZeroLeaks dashboard
  • Custom tooling — Integrate scans into your own pipelines
  • Research — Access probe library and knowledge base programmatically

Hosted SDK or local package?

Use @zeroleaks/sdk when you want managed attack orchestration connected to your real AI SDK, OpenAI, custom, or HTTP agent, complete tool traces, persisted reports, skill scans, and a single ZeroLeaks API key. Use this zeroleaks package when you want the scan engine itself to run locally with your own OpenRouter account and direct control over orchestration.

Read the hosted SDK documentation

Next Steps

On this page