v0.8.0
first real release. previous versions were alpha garbage.
what you get:
- scan any AI endpoint with one command
- fuzz RAG upload paths with poisoned PDFs (23 obfuscation strategies)
- multi-step attack chains in YAML
- 5-layer detection that doesn't flag refusals as crits
- 787 tests pass
what it found on a live GPT-4o-mini RAG chatbot: SSNs, Stripe keys,
DB connection strings, exfiltrated to an external webhook through
the AI's own tool calls. not a simulation.
pip install aipop