Open source · Free
Woodpecker: Open Source Red Teaming for AI, APIs, and K8s
Uncover security weaknesses across AI, agents, APIs, and Kubernetes before attackers do.
Three security domains
Full coverage of the modern stack
Customer-facing chatbots. Fraud-detection LLMs. Trading copilots. Underwriting agents. Every one of them is a live endpoint touching money, identity, and regulated data — and most legacy security tools were built before any of it existed.
Misconfigurations, privilege escalation, vulnerable deployment patterns.
Endpoint attacks, authentication flaws, over-permissions.
Prompt injection, jailbreaks, data poisoning, model leakage, agent boundaries via MCPs.
How it works
From simulated attack to actionable report
01
02
03
04
Connect
Point at a cluster, API, or LLM
Simulate
Real attacks executed safely
Detect
Vulnerabilities mapped by severity
Fix
Reports with compliance mapping
Woodpecker: Automated Red Teaming
Woodpecker provides flexible and extensible red teaming frameworks for K8s, APIs, and AI models/agents and enables multi-layer threat simulation across runtime, APIs, and LLM integrations.
Woodpecker covers prompt injection, jailbreaks, model theft, sensitive data leakage, and more. You can detect threats by testing malicious prompts originating from both adversarial and typical users and test for output manipulation as well as AI guardrails.
Woodpecker gives compliance coverage across threat vectors for OWASP top 10 for K8s, API, and AI, MITRE ATLAS, and NIST.
.png)


3%20%3D(Art)Kubed%20(16%20x%209%20in)%20(7)-p-1080.avif)

