Open source · Free

Woodpecker: Open Source Red Teaming for AI, APIs, and K8s

Uncover security weaknesses across AI, agents, APIs, and Kubernetes before attackers do.

Three security domains

Full coverage of the modern stack

Customer-facing chatbots. Fraud-detection LLMs. Trading copilots. Underwriting agents. Every one of them is a live endpoint touching money, identity, and regulated data — and most legacy security tools were built before any of it existed.

How it works

From simulated attack to actionable report

01
02
03
04
Connect
Point at a cluster, API, or LLM
Simulate
Real attacks executed safely
Detect
Vulnerabilities mapped by severity
Fix
Reports with compliance mapping

Woodpecker: Automated Red Teaming

Red Teaming Across Kubernetes, APIs, and AI Workflows
Woodpecker provides flexible and extensible red teaming frameworks for K8s, APIs, and AI models/agents and enables multi-layer threat simulation across runtime, APIs, and LLM integrations.
Geared for complete AI and LLM coverage
Woodpecker covers prompt injection, jailbreaks, model theft, sensitive data leakage, and more. You can detect threats by testing malicious prompts originating from both adversarial and typical users and test for output manipulation as well as AI guardrails.
Compliance Mapping for Regulatory Frameworks
Woodpecker gives compliance coverage across threat vectors for OWASP top 10 for K8s, API, and AI, MITRE ATLAS, and NIST.
Woodpecker Graph
GET STARTED

Join the Woodpecker flight

Let's make red teaming a default, not a privilege.