Skip to navigation

Changelog

Release history for the Check Point AI Red Teaming SDK (lakera-red-sdk), available for TypeScript and Python. TypeScript and Python move in sync for minor and major releases; version numbers refer to both unless a tab notes otherwise.

0.11.0

Released 2026-10-05.

  • Breaking: session.setConversationId is renamed to session.setSessionId, and the conversationId option of interceptTool to sessionId. setSessionId binds the scan session to your own session id, so activity reported by interceptTool joins the scan. See Trace Agent Tools.
  • Add session.relaySessionId, Red’s id for the relay session. session.id stays as a deprecated alias.
  • Add session.sessionId, which reads back the id set with session.setSessionId (undefined until set).
  • Support the tool-response-poisoning strategy. It tests indirect prompt injection: a benign request leads your agent to call a tool, and Red plants malicious content in the result interceptTool returns. interceptTool returns your real result outside these scans. This is the first version that can run them. See Tool Response Poisoning.

0.10.0

Released 2026-10-02.

  • Add responseTimeoutSeconds to createOrGetTarget and updateTarget. It sets how long Red waits for your handler to answer each prompt sent to that target, in whole seconds from 1 to 480 (8 minutes). Targets without it use the default, now 300 seconds (5 minutes) instead of 295. See Response Timeout.
  • Fix scans and recon stopping early against slow targets. The SDK stopped polling after 3 minutes without a new message, even while it was still waiting on the target’s reply, so later turns were never delivered and timed out. The idle timeout now only counts time with no message in flight.
  • Add SessionMessage.signal, an AbortSignal that aborts when Red stops waiting for that reply. Pass it to the calls that produce the reply so they stop too. A reply sent after that is dropped, the session ends, and scan.run() no longer waits for a handler that never returns.
  • Add tool tracing. interceptTool reports each tool call and its result to Red during a scan (observe-only — it returns the result unchanged), and session.setConversationId binds the scan session to your conversation id so the reported activity joins the scan. Off unless LAKERA_RED_TOOL_INTERCEPT is set. See Trace Agent Tools.

0.9.0

Released 2026-09-03.

  • ScanResultEntry.evaluation is now typed (Evaluation: attackSuccessIndicator, attackSuccessScore 0–5, explanation) instead of unknown, so callers can apply their own success thresholds.
  • Add ScanResultEntry.isSuccessful — server-computed verdict at the platform’s default success threshold, matching the dashboard.

0.8.0

Released 2026-08-14.

  • You can now provide ground-truth data for a target — its actual system prompt and tool definitions — so scans are generated and evaluated against what the target really does. Pass groundTruth (with systemPrompt and/or tools) to createOrGetTarget, or supply the same fields through appContextFile.

0.7.0

Released 2026-07-27.

  • Breaking: The recon profile now lives on the target. Pass appContext (or appContextFile) to createOrGetTarget, or omit it and pass a handler to run recon once when the target is created. createScan no longer accepts an application context — it references the target by name and reuses its stored profile.
  • Breaking: createTarget is renamed to createOrGetTarget, reflecting that it reuses an existing relay target of the same name instead of always creating a new one.

0.6.0

Released 2026-07-22 (TypeScript) and 2026-07-09 (Python).

  • Breaking: ReconContext.allowedActions and forbiddenActions are now string arrays instead of a single string. Each list is joined into a newline-separated string before being sent, for both appContext and appContextFile (YAML) inputs.

0.5.0

Released 2026-07-09.

  • Added customObjectives to the scan options — pass fully defined inline objectives without writing to the catalog first. Custom objectives can be combined with standard objective IDs in the same scan.
  • Added language to the scan options — set the language for attack generation (for example "fr" or "de"). Defaults to "en".

0.4.0

Released 2026-06-19 (TypeScript).

  • Added the getDashboardLink helper, which returns the AI Red Teaming dashboard URL for a scan.

0.3.0

Released 2026-06-03 (TypeScript).

  • HTTP 429 responses are retried with exponential back-off.
  • Added relay API support and contract tests.

0.2.0

Released 2026-05-22 (TypeScript) and 2026-06-19 (Python).

  • Added a bundled examples helper. Run npx lakera-red-sdk with init-examples or list-examples to copy the bundled examples into your project.
  • Logging improvements.

0.1.0

Initial release. TypeScript on 2026-05-18, Python on 2026-06-19.