OptionalattackOptionaldetectOptionalinjectionProbability (0.0-1.0) of applying a random encoding technique per turn. Default 0.0 (off).
OptionalmaxMaximum number of hard-refusal backtracks allowed per run. When
omitted, scales with totalTurns as max(1, floor(totalTurns / 3)) —
so a 30-turn run gets 10, a 5-turn run gets 1. Each backtrack
consumes a turn from the budget. Set explicitly to override.
OptionalmaxOptionalmetapromptOptionalmetapromptSeparate temperature for metaprompt/scoring calls. Defaults to temperature.
OptionalmetapromptOptionalmodelOptionalscoreScore target responses each turn to feed back into the attacker. Default true.
OptionalsuccessConsecutive turns >= threshold before triggering early exit. Default 2.
OptionalsuccessScore threshold (0-10) for early exit. Default 9. Set to undefined to disable.
OptionaltechniquesList of AttackTechnique instances to sample from. Defaults to all built-ins.
OptionaltemperatureOptionaltotal
Use pattern-based refusal detection to skip LLM scorer on obvious refusals. Default true.