Skip to main content
This page is the full command reference. For what Red Team does and which interfaces reach it, start with the Red Team Overview. Red Team goes beyond standard Harnesses by simulating realistic adversarial users. Personas define who is attacking, Policies define the rules Agents must follow, and Engagements execute multi-strategy attack sequences over several waves. Each Red Team run and its results share one evaluation_id. Use vijil evaluate to start the evaluation, then use vijil evaluations redteam-* to inspect it.

Start a Red Team Evaluation

Run a Red Team evaluation and wait for a terminal status:
The command prints progress while the evaluation runs. Its terminal statuses are succeeded, failed, cancelled, and degraded. A degraded evaluation finished with some attacker failures; inspect its status details before using the report. Add --no-wait to return immediately after creation. Save the evaluation ID from the output for later commands:

Configure the Evaluation

Pass a JSON object through --redteam to override the default wave settings:
The configuration accepts these fields: Red Team runs directly against the registered Agent. It does not accept --baseline, --bespoke, --sample-size, --local, or --harness-name.

Inspect Progress and Evidence

Each command accepts --team <team-id>. If you omit it, the CLI uses the default team from your configuration.

Status

Show the evaluation’s status, current phase, wave progress, attacker counts, errors, and degradation details:
Use the global output option before the command when you need JSON:

Seeds

Seeds describe the risks and instructions that attackers explore. List every seed or filter by wave:

Attacks

Attack results include the attacker type, execution status, transcript, and error details. List results by evaluation or wave:
Return one attack by combining --wave and --seed:

Judgments

Judgments record whether an attack succeeded, whether it could cause harm, and whether the response leaked artifacts:
Return one judgment by combining --wave and --seed:

Reflections

After each completed wave, the evaluation summarizes successful seeds, saturated outcomes, and new strategy patterns. List all reflections or select one wave:

Retrieve the Report

The final report summarizes vulnerabilities, policy violations, leaked artifacts, and successful strategies. JSON is the default format:
Choose Markdown or PDF with --format. Use --output to write the report to a file; PDF output requires it:
Add --force-regenerate to rebuild a cached PDF:
For the shared behavioral and Red Team startup options, see the CLI evaluation guide.

Red Team Engagements

A Red Team Engagement runs adversarial attacks against your Agent in waves, learning from each wave to plan the next. See Engagements for how the loop works.

vijil redteam create

Create and start an Engagement. Only --agent-id is required, because the service fetches the target endpoint and Agent card from the Agent registry.
Save the Engagement ID from the output:
--redteam controls the shape of the run, such as min_waves, max_waves, max_seeds_per_wave, and max_parallel_attackers. --advanced controls how hard each attacker works before giving up. Both map onto the Console sliders described in Run a Red Team Campaign. The exact JSON keys come from the vijil-redteam schemas package, so check vijil redteam create --help for the set your deployment accepts.

vijil redteam list

List Engagements for the active team, showing engagement_id, status, phase, and created_at.

vijil redteam status

Get one Engagement’s live state, including phase, current wave, attackers completed, and attackers errored.

vijil redteam results

Get the aggregated results for an Engagement.

vijil redteam cancel

Cancel a running Engagement.

vijil redteam delete

Delete an Engagement.

vijil redteam seeds

List the attack seeds generated for an Engagement, showing wave_id, seed_id, instruction, and risk_type.

vijil redteam attacks

List attacker runs, showing wave_id, seed_id, attacker_type, and status.

vijil redteam attack

Get one attacker run, including its strategy and transcript.

vijil redteam judgments

List judgments, showing wave_id, seed_id, is_success, and potential_harm.

vijil redteam judgment

Get one judgment in full.

vijil redteam reflections

List every wave’s reflection, which is the Engagement’s own account of what worked.

vijil redteam reflection

Get one wave’s reflection.

vijil redteam report

Get the final report, with clustered vulnerabilities, policy violations, leaked artifacts, and successful strategies.

vijil redteam report-md

Get the final report rendered as Markdown, which is convenient for pasting into tickets.
Last modified on September 30, 2026