FORGE: Open Source AI Security Testing Framework for LLM Systems

FORGE (Framework for Orchestrated Reasoning & Generation of Engines) is an open source autonomous AI security testing framework for LLM systems that runs 24/7 and covers OWASP LLM Top 10 vulnerabilities.
Key Features
- Builds its own tools mid-run — generates custom Python modules on the spot when encountering unknown vulnerabilities
- Self-replicates into a swarm — creates subprocess copies that share a live hive mind
- Learns from every session — uses SQLite to store patterns, AI scores findings, and genetic algorithms evolve its own prompts
- AI pentesting AI — 7 modules covering OWASP LLM Top 10 vulnerabilities
- Honeypot — fake vulnerable AI endpoint that catches attackers and classifies whether they're human or AI agent
- 24/7 monitor — watches AI in production, alerts on latency spikes, attack bursts, and injection attempts via Slack/Discord webhook
- Stress tester — OWASP LLM04 DoS resilience testing with live TPS dashboard and A-F grade
- Works on any model — Claude, Llama, Mistral, DeepSeek, GPT-4, Groq, anything — one environment variable to switch
OWASP LLM Top 10 Coverage
- LLM01 Prompt Injection → prompt_injector + jailbreak_fuzzer (125 payloads)
- LLM02 Insecure Output → rag_leaker
- LLM04 Model DoS → overloader (8 stress modes)
- LLM06 Sensitive Disclosure → system_prompt_probe + rag_leaker
- LLM07 Insecure Plugin → agent_hijacker
- LLM08 Excessive Agency → agent_hijacker
- LLM10 Model Theft → model_fingerprinter
Setup and Usage
Installation commands:
git clone https://github.com/umangkartikey/forge
cd forge
pip install anthropic rich
export ANTHROPIC_API_KEY=your_keyRun with local Ollama for free:
FORGE_BACKEND=ollama FORGE_MODEL=llama3.1 python forge.pyThe tool addresses common LLM security gaps: most AI apps deployed today have never been red teamed, system prompts are fully extractable, jailbreaks work, RAG pipelines leak, and indirect prompt injection via tool outputs is almost universally unprotected. FORGE automates finding these vulnerabilities the same way a human red teamer would, but faster and running 24/7.
📖 Read the full source: r/LocalLLaMA
👀 See Also

Audit Your Claude Code Permissions: A Practical Guide to Scoping Tool Access
A Reddit user audited their Claude Code setup and found over-permissioned tools that could edit .env files and production configs. Practical steps: audit global vs. per-project tools, check CLAUDE.md for secrets, and scope file access per directory.

Claude Code Install Phishing Site Tops Google Search Results
A phishing site impersonating the official Claude Code download page appears as the first Google result for "Claude code install mac." Users are warned not to download from the fake site.

OpenClaw's 'Allow Always' Feature Security Flaws and Safer Alternatives
OpenClaw's 'allow always' approval feature has been the subject of two CVEs this month, allowing unauthorized command execution through wrapper command binding and shell line-continuation bypasses. The deeper issue is how the feature trains users to stop paying attention to security prompts.

Zero-Trust OpenClaw Architecture Adds Pre-Execution Authorization and Post-Execution Verification
An open-source architecture for OpenClaw adds two security checkpoints: a Rust sidecar that intercepts tool calls before execution with sub-millisecond authorization overhead, and deterministic post-execution verification using assertions instead of LLM judgment. The system includes tracing with DOM snapshots and screenshots, plus a DOM compression skill that reduces token usage by 90-99%.