Jailbreak research tools
Free, no signup, no account. Everything on this page runs in your browser and stays there. These are reference tools for people who read jailbreak research, not attack tooling.
A faceted, searchable catalog of 65 jailbreak technique classes. Filter by the behavioural property each one exploits, by modality, by first-seen year, by patch status, and by which model families still resist it. Every record links to its primary disclosure and to the analysis on this site.
Index and references only. No working payload strings are published.
Plain definitions for the terms the literature uses inconsistently — attack success rate, refusal suppression, adversarial suffix, indirect injection, and the rest.
56 entries.
Search every article on this site, including source titles and technique names, without leaving the page.
Start with these
If you arrived looking for a specific technique class rather than a tool, these are the most-read entries on the site.
- Universal adversarial suffixes: how the GCG attack works
- Automated jailbreak attacks: GCG, AutoDAN, PAIR, TAP
- AI jailbreak testing: HarmBench, JailbreakBench, StrongREJECT
- Crescendo and multi-turn jailbreaks
- How to detect jailbreak prompts: the three layers
- Best LLM red team tools: garak, PyRIT and promptfoo compared
- Promptfoo alternatives for LLM red teaming