> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.lakera.ai/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.lakera.ai/_mcp/server.

# Changelog

Release history for the Check Point AI Red Teaming SDK (`lakera-red-sdk`), available for
[TypeScript](https://www.npmjs.com/package/lakera-red-sdk) and
[Python](https://pypi.org/project/lakera-red-sdk/). TypeScript and Python move in sync
for minor and major releases; version numbers refer to both unless a tab notes
otherwise.

## 0.11.0

Released 2026-10-05.

#### TypeScript

* **Breaking:** `session.setConversationId` is renamed to `session.setSessionId`, and
  the `conversationId` option of `interceptTool` to `sessionId`. `setSessionId` binds
  the scan session to your own session id, so activity reported by `interceptTool` joins
  the scan. See [Trace Agent Tools](/docs/red/trace-agent-tools).
* Add `session.relaySessionId`, Red's id for the relay session. `session.id` stays as a
  deprecated alias.
* Add `session.sessionId`, which reads back the id set with `session.setSessionId`
  (`undefined` until set).
* Support the `tool-response-poisoning` strategy. It tests indirect prompt injection: a
  benign request leads your agent to call a tool, and Red plants malicious content in
  the result `interceptTool` returns. `interceptTool` returns your real result outside
  these scans. This is the first version that can run them. See
  [Tool Response Poisoning](/docs/red/sdk-reference#tool-response-poisoning).

#### Python

* **Breaking:** `session.set_conversation_id` is renamed to `session.set_session_id`,
  and the `conversation_id` argument of `intercept_tool` to `session_id`.
  `set_session_id` binds the scan session to your own session id, so activity reported
  by `intercept_tool` joins the scan. See
  [Trace Agent Tools](/docs/red/trace-agent-tools).
* Add `session.relay_session_id`, Red's id for the relay session. `session.id` stays as
  a deprecated alias.
* Add `session.session_id`, which reads back the id set with `session.set_session_id`
  (`None` until set).
* Support the `tool-response-poisoning` strategy
  (`ToolResponsePoisoningStrategyOptions`). It tests indirect prompt injection: a benign
  request leads your agent to call a tool, and Red plants malicious content in the
  result `intercept_tool` returns. `intercept_tool` returns your real result outside
  these scans. This is the first version that can run them. See
  [Tool Response Poisoning](/docs/red/sdk-reference#tool-response-poisoning).

## 0.10.0

Released 2026-10-02.

#### TypeScript

* Add `responseTimeoutSeconds` to `createOrGetTarget` and `updateTarget`. It sets how
  long Red waits for your handler to answer each prompt sent to that target, in whole
  seconds from 1 to 480 (8 minutes). Targets without it use the default, now 300 seconds
  (5 minutes) instead of 295. See
  [Response Timeout](/docs/red/sdk-reference#response-timeout).
* Fix scans and recon stopping early against slow targets. The SDK stopped polling after
  3 minutes without a new message, even while it was still waiting on the target's
  reply, so later turns were never delivered and timed out. The idle timeout now only
  counts time with no message in flight.
* Add `SessionMessage.signal`, an `AbortSignal` that aborts when Red stops waiting for
  that reply. Pass it to the calls that produce the reply so they stop too. A reply sent
  after that is dropped, the session ends, and `scan.run()` no longer waits for a
  handler that never returns.
* Add tool tracing. `interceptTool` reports each tool call and its result to Red during
  a scan (observe-only — it returns the result unchanged), and
  `session.setConversationId` binds the scan session to your conversation id so the
  reported activity joins the scan. Off unless `LAKERA_RED_TOOL_INTERCEPT` is set. See
  [Trace Agent Tools](/docs/red/trace-agent-tools).

#### Python

* Add `response_timeout_seconds` to `create_or_get_target` and `update_target`. It sets
  how long Red waits for your handler to answer each prompt sent to that target, in
  whole seconds from 1 to 480 (8 minutes). Targets without it use the default, now 300
  seconds (5 minutes) instead of 295. See
  [Response Timeout](/docs/red/sdk-reference#response-timeout).
* Fix scans and recon stopping early against slow targets. The SDK stopped polling after
  3 minutes without a new message, even while it was still waiting on the target's
  reply, so later turns were never delivered and timed out. The idle timeout now only
  counts time with no message in flight.
* Cancel the handler task when Red stops waiting for its reply. A reply sent after that
  is dropped, the session ends, and `scan.run()` no longer waits for a handler that
  never returns.
* Add tool tracing. `intercept_tool` reports each tool call and its result to Red during
  a scan (observe-only — it returns the result unchanged), and
  `session.set_conversation_id` binds the scan session to your conversation id so the
  reported activity joins the scan. Off unless `LAKERA_RED_TOOL_INTERCEPT` is set. See
  [Trace Agent Tools](/docs/red/trace-agent-tools).

## 0.9.0

Released 2026-09-03.

#### TypeScript

* `ScanResultEntry.evaluation` is now typed (`Evaluation`: `attackSuccessIndicator`,
  `attackSuccessScore` 0–5, `explanation`) instead of `unknown`, so callers can apply
  their own success thresholds.
* Add `ScanResultEntry.isSuccessful` — server-computed verdict at the platform's default
  success threshold, matching the dashboard.

#### Python

* `ScanResultEntry.evaluation` is now typed (`Evaluation`: `attack_success_indicator`,
  `attack_success_score` 0–5, `explanation`) instead of `Any`, so callers can apply
  their own success thresholds.
* Add `ScanResultEntry.is_successful` — server-computed verdict at the platform's
  default success threshold, matching the dashboard.

## 0.8.0

Released 2026-08-14.

#### TypeScript

* You can now provide ground-truth data for a target — its actual system prompt and tool
  definitions — so scans are generated and evaluated against what the target really
  does. Pass `groundTruth` (with `systemPrompt` and/or `tools`) to `createOrGetTarget`,
  or supply the same fields through `appContextFile`.

#### Python

* You can now provide ground-truth data for a target — its actual system prompt and tool
  definitions — so scans are generated and evaluated against what the target really
  does. Pass `ground_truth` (with `system_prompt` and/or `tools`) to
  `create_or_get_target`, or supply the same fields through `app_context_file`.

## 0.7.0

Released 2026-07-27.

#### TypeScript

* **Breaking:** The recon profile now lives on the target. Pass `appContext` (or
  `appContextFile`) to `createOrGetTarget`, or omit it and pass a handler to run recon
  once when the target is created. `createScan` no longer accepts an application context
  — it references the target by name and reuses its stored profile.
* **Breaking:** `createTarget` is renamed to `createOrGetTarget`, reflecting that it
  reuses an existing relay target of the same name instead of always creating a new one.

#### Python

* **Breaking:** The recon profile now lives on the target. Pass `app_context` (or
  `app_context_file`) to `create_or_get_target`, or omit it and pass a handler to run
  recon once when the target is created. `create_scan` no longer accepts an application
  context — it references the target by name and reuses its stored profile.
* **Breaking:** `create_target` is renamed to `create_or_get_target`, reflecting that it
  reuses an existing relay target of the same name instead of always creating a new one.

## 0.6.0

Released 2026-07-22 (TypeScript) and 2026-07-09 (Python).

#### TypeScript

* **Breaking:** `ReconContext.allowedActions` and `forbiddenActions` are now string
  arrays instead of a single string. Each list is joined into a newline-separated string
  before being sent, for both `appContext` and `appContextFile` (YAML) inputs.

#### Python

* **Breaking:** `ReconContext.allowed_actions` and `forbidden_actions` are now
  `list[str]` instead of a single string. Each list is joined into a newline-separated
  string before being sent, for both `app_context` and `app_context_file` (YAML) inputs.

## 0.5.0

Released 2026-07-09.

#### TypeScript

* Added `customObjectives` to the scan options — pass fully defined inline objectives
  without writing to the catalog first. Custom objectives can be combined with standard
  objective IDs in the same scan.
* Added `language` to the scan options — set the language for attack generation (for
  example `"fr"` or `"de"`). Defaults to `"en"`.

#### Python

* Added `custom_objectives` to the scan options — pass fully defined inline objectives
  without writing to the catalog first. Custom objectives can be combined with standard
  objective IDs in the same scan. (Python released this as 0.3.0 on 2026-07-09.)
* Added `language` to the scan options — set the language for attack generation (for
  example `"fr"` or `"de"`). Defaults to `"en"`.

## 0.4.0

Released 2026-06-19 (TypeScript).

#### TypeScript

* Added the `getDashboardLink` helper, which returns the AI Red Teaming dashboard URL
  for a scan.

#### Python

* The equivalent `get_dashboard_link` helper shipped in the Python SDK's 0.2.0 release
  (2026-06-19).

## 0.3.0

Released 2026-06-03 (TypeScript).

#### TypeScript

* HTTP 429 responses are retried with exponential back-off.
* Added relay API support and contract tests.

#### Python

* No corresponding Python release; these changes were TypeScript-only.

## 0.2.0

Released 2026-05-22 (TypeScript) and 2026-06-19 (Python).

#### TypeScript

* Added a bundled examples helper. Run `npx lakera-red-sdk` with `init-examples` or
  `list-examples` to copy the bundled examples into your project.
* Logging improvements.

#### Python

* Added the `get_dashboard_link` helper, which returns the AI Red Teaming dashboard URL
  for a scan.
* Added runnable `echo` and `chatbot` examples.

## 0.1.0

Initial release. TypeScript on 2026-05-18, Python on 2026-06-19.