I build RedThread, an open-source CLI for a narrow kind of LLM-agent test. A model can read hostile text from a page, document, or tool result and later form a tool call that was never part of the job. Looking only at the final response hides the causal chain. Looking only at the tool result can hide whether the model tried. RedThread preserves the context slice, tool schema, proposed call, response, and score in a replayable case. That does not make every odd output a vulnerability. It gives the next person enough to rerun the claim. https://github.com/matheusht/redthread submitted by /u/Apprehensive-Zone148
Originally posted by u/Apprehensive-Zone148 on r/ArtificialInteligence
You must log in or # to comment.
