Tools

Kailash tool set

Three provenance streams: the CLASSIC layer follows the Kali heritage catalog re-derived for a software-only scope; DEFENCE/OPS draw on nixpkgs’ own staple set (reproducible infrastructure, not curated exotica); ATTACK and the specialised edges of every layer draw on upstream research tooling (garak, PyRIT, promptfoo, ART, counterfit), pinned commit-exact through nvfetcher — never floated.

Selection criterion: fit to the four pillars — AppSec (classic software assessment), APISec (web/API/AI-endpoint runtime assessment), MLSec (adversarial ML against predictive models), AISec (LLM, agentic, MCP security). Every tool lands in exactly one primary category; dual-use tools carry secondary_categories cross-refs, never duplicate rows.

Excluded (the §3.7 no-resurrection guard): hardware/RF/wifi/bluetooth tooling (one opt-in exception: the c-07 SDR data-pack), paid-licence tools, cloud-only SaaS, unmaintained tools, and classic-network attack tooling (lateral movement, C2 frameworks, social engineering) — Kali’s network-arsenal territory, not the four pillars.

32 taxonomy rows — 31 categories + 1 opt-in data-pack (c-07-signal-sdr) — and 336 tool rows: CLASSIC 146, ATTACK 58, OPS 87, DEFENCE 45. The §3.6 census projected ~337 primary slots; 330 are filled, the open planned slots noted per section below.

Generated — never hand-maintained. python3 tools/generate-tools-page.py fetches tools.yaml + categories.yaml from kailash-packages and renders every number, table, and link here at generation time; manifest merges regenerate this page.

What every value means

Every field a tool row can carry, in manifest order. The In column is the live count of the 336 tool rows carrying the field at this revision; a smaller count means the field is optional and present only where it applies.

Field In Meaning
id 336/336 Unique slug — the row’s key on every generated surface (menu, CLI, modules, docs, derivations).
layer 336/336 CLASSIC · ATTACK · DEFENCE · OPS (the platform layer, formerly BUILD — os#121). All four ride a CORE substrate with no tool categories.
category 336/336 Primary category id — exactly one per row (the one-tool-one-primary invariant); orders the 31 sections on this page.
secondary_categories 23/336 Optional cross-refs where dual-use is real — never a second primary. Shown as the also line in the tables.
name 336/336 Human name (menu/docs surface); equals id on all rows but one.
description 336/336 One-line what-it-does, hand-written in the manifest; truncated in the tables.
source 320/336 Upstream coordinates {vcs_owner, repo, vcs_url}; research-grade tools pin commit-exact (nvfetcher, _sources/). Absent on 16 rows with no declared upstream URL — those render unlinked.
license 336/336 SPDX identifier (GPL-2.0-only, MIT, …).
packaging 336/336 status (vocabulary below) + derivation path on bespoke rows (122).
safety 336/336 level (vocabulary below) + target-required bool — inert without a declared target; keys the OS-side double gate.
nixos_menu 336/336 Desktop-menu surface {icon, exec, category}.
docs 336/336 Generated docs path: layers/<category>/<tool>.md.
tags 336/336 Lowercase list: shape/stage markers + the update:* cadence class (below).
atlas_tactics 58/336 ≥1 MITRE ATLAS tactic id (AML.T…, 2026.05 matrix) — ATTACK rows only.
owasp_llm 58/336 Dual-epoch OWASP LLM Top 10 map {2026: […], v2: […]} — ATTACK rows only; the epochs are recorded separately and never mixed (§2.4).

packaging.status

Status Count Meaning
native 336 nixpkgs ships it; the row records the upstream coordinates the lock builds from.
stale 7 nixpkgs-native; the packaged version trails upstream (tracked through the update cadence, not forked).
bespoke 122 Packaged in this overlay: nvfetcher commit-exact pin, pkgs/<tool>/default.nix, _sources/ committed.
module 16 Delivered as a bundled module/component (service- or library-shape), not a single menu executable.
data 29 Data artefact — wordlists, corpora, pack seeds; typically an opt-in data-pack row.

safety.level

Level Count Meaning
safe 290 Runs as-is — works on artefacts, local models, or one’s own systems.
requires-target 20 Must be pointed at a system under test — authorised engagements only.
exp 26 Experimental research code — lab releases; double-gated on the OS side (kailash.labMode = true + KAILASH_LAB_MODE=1).

target-required (12 of 336 rows, all ATTACK) — inert without a target; renders as the · target-required marker in the Safety column.

Tag update classes

The update:* tag on a row is the update-automation cadence class — how aggressively the tool’s pin follows upstream. Live distribution at this revision:

Tag Rows
update:slow 199 — The bulk cadence — steady availability, not per-commit tracking.
update:steady 13 — Tighter tracking, not release-pinned.
update:weekly 5 — Weekly follow — fast-moving attack tooling.
update:fast 6 — Tightest follow — pinned-reference tools kept near upstream head.

C-1 · Information Gathering (c-01-information-gathering, CLASSIC, 38 tools)

Purpose: Classic recon/OSINT lead-in for AI engagements — the AI-surface on-ramp.

Coverage: High

Tool Licence Packaging Safety Description
nmap GPL-2.0-only native safe Network scanner and security mapper — host/port discovery and service enumeration.
masscan AGPL-3.0-only native safe Mass IP port scanner — the whole internet in minutes.
rustscan GPL-3.0-only native safe Fast port scanner that pipes results into Nmap.
zenmap GPL-2.0-only native safe Official Nmap Security Scanner GUI.
the-harvester GPL-2.0-only native safe Gathers emails, subdomains and names from public sources.
amass Apache-2.0 native safe In-depth DNS enumeration and network mapping (OWASP Amass).
recon-ng GPL-3.0-only native safe Full-featured reconnaissance framework with a web-style module environment.
sublist3r GPL-2.0-only bespoke · pkgs/sublist3r/default.nix safe Subdomain enumeration using public search engines and services.
maltego-community LicenseRef-Proprietary native safe OSINT graph platform — community edition, unfree licence.
dmitry GPL-2.0-or-later native safe Deepmagic information-gathering tool — whois, subdomains, emails.
fierce GPL-3.0-or-later native safe DNS reconnaissance for locating non-contiguous IP space.
dnsrecon GPL-2.0-only bespoke · pkgs/dnsrecon/default.nix safe DNS enumeration script — zone transfers, records, reverse lookups (overlay pin).
dnsenum GPL-2.0-or-later native safe Enumerates DNS information including subdomains.
dnsmap GPL-3.0-only native safe Scans for subdomains using brute-force techniques.
massdns GPL-3.0-only native safe Resolves large amounts of domain names.
assetfinder MIT native safe Finds domains and subdomains related to a given domain.
findomain GPL-3.0-or-later stale safe Fastest cross-platform subdomain enumerator.
gobuster Apache-2.0 native safe Brute-forces URIs, DNS subdomains, virtual hosts and open ports.
dirb GPL-2.0-only native safe Web content scanner.
dirsearch GPL-2.0-only native safe Command-line web-path brute-forcer for directories and files.
feroxbuster MIT native safe Recursive content discovery tool (Rust).
ffuf MIT native safe Fast web fuzzer written in Go.
wfuzz GPL-2.0-only native safe Web content fuzzer for web application assessment.
whatweb GPL-2.0-only native safe Next-generation web scanner — technology fingerprinting.
wafw00f BSD-3-Clause native safe Identifies and fingerprints web application firewalls.
arjun GPL-3.0-only native safe HTTP parameter discovery suite.
uro Apache-2.0 native safe Declutters URL lists for crawling and pentesting.
photon GPL-3.0-only native safe Lightning-fast web crawler extracting URLs and OSINT intel.
sherlock MIT native safe Hunts down social-media accounts by username across sites.
spiderfoot MIT bespoke · pkgs/spiderfoot/default.nix safe OSINT automation platform — collects intel about a target from public sources.
httpx MIT stale safe Fast and multi-purpose HTTP toolkit.
gospider MIT native safe Fast web spider written in Go.
hakrawler GPL-3.0-only native safe Web crawler for endpoint and asset discovery.
arp-scan GPL-3.0-only native safe ARP scanning and fingerprinting tool (ethernet, not RF).
netdiscover GPL-3.0-or-later native safe Network address discovery via ARP — kept per the §3.2 ethernet rule.
katana MIT stale safe Next-generation crawling and spidering framework.
subfinder MIT bespoke · pkgs/subfinder/default.nix safe Subdomain discovery tool — overlay pin (pkgs/subfinder, KA-02.3).
puredns GPL-3.0-only stale safe Domain resolver and subdomain brute-forcing tool.

C-2 · Vulnerability Analysis (c-02-vulnerability-analysis, CLASSIC, 7 tools)

Purpose: Local vulnerability scanning of software artefacts and hosts.

Coverage: Medium

Tool Licence Packaging Safety Description
nikto GPL-2.0-or-later native safe Web server scanner performing tests for dangerous files and misconfigurations.
lynis GPL-3.0-only native safe Security auditing tool for Linux, macOS and UNIX systems.
wapiti GPL-2.0-only native safe Web application vulnerability scanner.
legion GPL-3.0-only bespoke · pkgs/legion/default.nix safe Semi-automated network pentesting framework with a GUI.
searchsploit MIT native safe Exploit Database search CLI (ships with the exploitdb archive).
nuclei MIT stale safe Configurable targeted vulnerability scanner — overlay-currency class.
gvm AGPL-3.0-only module safe Greenbone Vulnerability Management — ships as services.kailash.gvm, not loose tools.

C-3 · Web Application Assessment (c-03-web-application-assessment, CLASSIC, 10 tools)

Purpose: Web/API proxy-based assessment and scanning.

Coverage: Medium-High

Tool Licence Packaging Safety Description
burpsuite LicenseRef-Proprietary native safe Integrated platform for web security testing — free edition, pinned (KA-07.1).
zaproxy
also: c-10-runtime-appsec-ai
Apache-2.0 native safe OWASP ZAP — web app penetration-testing proxy.
caido LicenseRef-Proprietary native safe Lightweight web security auditing toolkit (free tier), pinned (KA-07.1).
graphw00f BSD-3-Clause native safe GraphQL server engine fingerprinting utility.
clairvoyance Apache-2.0 native safe Obtains GraphQL API schemas from introspection-disabled endpoints.
inql
also: c-04-database-assessment
Apache-2.0 bespoke · pkgs/inql/default.nix safe Security testing tool for GraphQL — query/schema analysis.
kiterunner AGPL-3.0-only native safe Contextual content discovery tool for API routes.
gopherus GPL-3.0-only bespoke · pkgs/gopherus/default.nix safe Generates serialized payloads for SSRF/gopher attacks on internal services.
commix
also: c-08-exploitation-post-exploitation
GPL-3.0-or-later native safe Automated all-in-one OS command-injection exploitation tool.
sstimap GPL-3.0-only bespoke · pkgs/sstimap/default.nix safe SSTI detection and exploitation assistant (Server-Side Template Injection).

C-4 · Database Assessment (c-04-database-assessment, CLASSIC, 7 tools)

Purpose: Database front-end assessment tooling.

Coverage: High

Tool Licence Packaging Safety Description
sqlmap
also: c-03-web-application-assessment
GPL-2.0-or-later native safe Automatic SQL injection and database takeover tool.
mssql-cli BSD-3-Clause bespoke · pkgs/mssql-cli/default.nix safe Command-line interface for SQL Server with autocompletion.
psql PostgreSQL native safe Interactive terminal for PostgreSQL — front-end enumeration support.
redis-cli MIT native safe Redis command-line client — front-end enumeration support.
mongosh Apache-2.0 native safe MongoDB Shell — front-end enumeration support.
sqlitebrowser GPL-3.0-only native safe DB Browser for SQLite — artefact inspection front-end.
mycli BSD-3-Clause native safe Command-line interface for MySQL with autocompletion.

C-5 · Password & Offline-Credential Attacks (c-05-password-offline-credential, CLASSIC, 15 tools)

Purpose: Offline credential attacks (hashes, dumps, artefacts).

Coverage: High

Tool Licence Packaging Safety Description
hashcat MIT native safe Fast password cracker with GPU support and a rule-based engine.
john GPL-2.0-or-later native safe John the Ripper password cracker (Jumbo build).
johnny BSD-2-Clause native safe Open-source GUI frontend for John the Ripper.
ophcrack GPL-2.0-or-later native safe Windows password cracker based on rainbow tables.
crunch GPL-2.0-only native safe Wordlist generator.
cewl GPL-3.0-or-later native safe Custom wordlist generator that spiders a target URL.
maskgen BSD-3-Clause bespoke · pkgs/maskgen/default.nix safe Generates optimized hashcat masks from password lists (PACK kit).
policygen BSD-3-Clause bespoke · pkgs/policygen/default.nix safe Generates hashcat mask policies from password-policy samples (PACK kit).
statsgen BSD-3-Clause bespoke · pkgs/statsgen/default.nix safe Password-list statistics generator for mask analysis (PACK kit).
hashid GPL-3.0-or-later native safe Identifies hash types from their format.
hash-identifier GPL-3.0-or-later native safe Identifies the hash algorithm used to encrypt data.
bopscrk GPL-3.0-only bespoke · pkgs/bopscrk/default.nix safe Smart wordlist generator that combines target-related words with transformations.
rsmangler CC-BY-SA-2.0 native safe Performs various manipulations on wordlists (mangling).
twofi CC-BY-SA-2.0 bespoke · pkgs/twofi/default.nix safe Twofi — words of interest from Twitter for password cracking lists.
seclists MIT data safe Collection of security wordlists (passwords, usernames, URLs) — the opt-in wordlist pack seed row for KA-07.2.

C-6 · Reverse Engineering (software artefacts) (c-06-reverse-engineering, CLASSIC, 26 tools)

Purpose: Binary/app artefact RE — software only.

Coverage: Very High

Tool Licence Packaging Safety Description
ghidra Apache-2.0 native safe Software reverse-engineering suite of tools (NSA).
radare2 LGPL-3.0-only native safe UNIX-like reverse-engineering framework and command-line toolset.
rizin GPL-3.0-or-later native safe UNIX-like reverse-engineering framework (radare2 fork).
cutter GPL-3.0-only native safe Free and open-source reverse-engineering platform powered by rizin.
iaito GPL-3.0-only native safe Official radare2 GUI.
gdb GPL-3.0-or-later native safe GNU Project debugger.
gef MIT native safe GDB Enhanced Features — exploit-development plugin for GDB.
pwndbg MIT native safe Exploit-development plugin for GDB with modern UX.
peda LicenseRef-Unknown bespoke · pkgs/peda/default.nix safe Python Exploit Development Assistance for GDB (upstream has no SPDX file).
capstone BSD-3-Clause native safe Lightweight multi-platform CPU disassembly framework.
cstool BSD-3-Clause native safe Capstone’s interactive disassembly CLI.
checksec BSD-3-Clause native safe Checks security properties of executables (RELRO/canary/NX/PIE).
jadx Apache-2.0 native safe Dex to Java decompiler.
bytecode-viewer GPL-3.0-only native safe Java/Android bytecode viewer, decompiler and editor.
apktool Apache-2.0 native safe Reverse-engineers Android APK files (decode/rebuild).
dex2jar Apache-2.0 native safe Converts Android .dex files to Java .class (jar).
javasnoop GPL-3.0-only bespoke · pkgs/javasnoop/default.nix safe Intercepts methods and alters data in Java applications at runtime.
jd-gui GPL-3.0-only bespoke · pkgs/jd-gui/default.nix safe Java decompiler with a standalone graphical UI.
smali LicenseRef-Unknown native safe Assembler/disassembler for the Android dex format (upstream carries no SPDX licence file; AOSP mirror maps Apache-2.0).
unicorn GPL-2.0-only native safe Lightweight multi-architecture CPU emulator framework.
angr BSD-2-Clause native safe Binary analysis framework — symbolic execution and emulation.
qiling GPL-2.0-only native safe Cross-platform emulation framework built on Unicorn.
unipacker GPL-2.0-only bespoke · pkgs/unipacker/default.nix safe Automatic and platform-independent unpacker for Windows binaries.
pyinstaller-extractor GPL-3.0-or-later bespoke · pkgs/pyinstaller-extractor/default.nix safe Extracts packed executables from PyInstaller bundles.
edb-debugger GPL-2.0-or-later native safe Cross-platform AArch32/x86/x86-64 debugger.
binwalk MIT native safe Firmware-image analysis — signature scanning and extraction.

C-7 · Signal & SDR Processing (c-07-signal-sdr, CLASSIC data-pack, 6 tools)

Purpose: Software-only signal processing pack for ML signal work (audio/waveform corpora) and the B-6 voice-clone research surface.

Coverage: Medium

Opt-in data-pack. This category ships as the opt-in data-pack kailash-data.sdr-tools — its tools are absent from default profiles and ISOs by design; the module stub exists but is switched off on every default surface. Manifest note: the sole radio-adjacent concession (§4.1); category of record but opt-in data-pack — never on default profiles/ISOs (D7). Module stub exists but off everywhere by default; decision + revisit condition recorded in the module comment (KA-07.2).

Tool Licence Packaging Safety Description
gnuradio GPL-3.0-only data safe GNU Radio — software-defined radio DSP framework (software-only).
gqrx GPL-3.0-or-later data safe Software-defined radio receiver built on GNU Radio.
hackrf-tools GPL-2.0-or-later data safe Command-line utilities for HackRF hardware SDR platforms.
sox GPL-2.0-or-later data safe Sound eXchange — audio processing and format conversion.
librosa ISC data safe Audio and music-signal analysis library (Python).
pysox BSD-3-Clause bespoke · pkgs/pysox/default.nix safe Python bindings around SoX for audio DSP pipelines.

C-8 · Exploitation & Post-Exploitation (software) (c-08-exploitation-post-exploitation, CLASSIC, 9 tools)

Purpose: Software-target exploitation, webshells, privesc/post-exploitation.

Coverage: Medium

Tool Licence Packaging Safety Description
metasploit-framework BSD-3-Clause native safe Exploit framework — pinned upstream (KA-07.3); web/API modules only.
msfvenom BSD-3-Clause native safe Payload generation and encoding CLI from the Metasploit suite.
beef-xss GPL-2.0-only native safe Browser Exploitation Framework — XSS hooking and browser assessment.
weevely GPL-3.0-or-later native safe Weaponized web shell with a telnet-like console.
laudanum GPL-2.0-or-later native safe Collection of ready-to-use injectable web-shell files.
webshell-analysis-pack LicenseRef-Unknown data safe Reference pack of known webshell artefacts for detection and analysis.
peass-ng GPL-2.0-or-later native safe Privilege-escalation awesome scripts suite (linpeas/winpeas).
unix-privesc-check GPL-2.0-or-later native safe Finds misconfigurations allowing local privilege escalation.
pspy
also: c-09-forensics-ir-reporting
GPL-3.0-only native safe Monitors Linux processes without root permissions.

C-9 · Forensics, IR & Reporting (c-09-forensics-ir-reporting, CLASSIC, 21 tools)

Purpose: Artefact forensics, incident response, engagement reporting.

Coverage: Medium-High

Tool Licence Packaging Safety Description
autopsy Apache-2.0 native safe Digital forensics platform and GUI for The Sleuth Kit.
sleuthkit CPL-1.0 native safe Library and CLI collection for filesystem forensics analysis.
volatility3 VSL-1.0 native safe Memory forensics framework (Volatility 3).
hashdeep GPL-2.0-only native safe Hashing and audit utility with fuzzy matching (md5deep family).
chkrootkit GPL-2.0-or-later bespoke · pkgs/chkrootkit/default.nix safe Locally checks for signs of a rootkit.
rkhunter GPL-2.0-or-later bespoke · pkgs/rkhunter/default.nix safe Rootkit Hunter — scans for rootkits, backdoors and local exploits.
dc3dd GPL-3.0-or-later native safe Forensic disk-imaging tool (DoD Cyber Crime Center fork of dd).
ewfacquire LGPL-3.0-only native safe Acquires evidence in the Expert Witness Compression Format (libewf).
guymager GPL-2.0-only native safe Fast forensic imager with a graphical interface.
regripper MIT native safe Windows registry forensics — extracting artefacts from hives.
testdisk GPL-2.0-or-later native safe Data-recovery tool for lost partitions and filesystems.
photorec GPL-2.0-or-later native safe File-carving recovery tool shipped with TestDisk.
bulk_extractor MIT native safe Extracts features (emails, URLs, cards) from disk images without parsing the filesystem.
chainsaw GPL-3.0-only stale safe Rapidly searches and hunts through Windows forensic artefacts (Sigma/YARA).
hayabusa AGPL-3.0-only stale safe Windows event-log fast forensics timeline generator.
sigma-cli LGPL-2.1-or-later native safe Sigma rule conversion command-line interface.
sysmon-modular MIT data safe A modular Sysmon configuration set for high-fidelity Windows logging.
plaso Apache-2.0 bespoke · pkgs/plaso/default.nix safe log2timeline — super-timeline generation and analysis.
timesketch Apache-2.0 module safe Collaborative forensic timeline analysis — ships as a service module.
faraday
also: o-06-documentation-reporting-authoring
MIT module safe Vulnerability-management and collaborative IR platform — service module.
pwndoc-ng
also: o-06-documentation-reporting-authoring
MIT module safe Collaborative pentest reporting platform — service module.

C-10 · Runtime AppSec for AI Systems (c-10-runtime-appsec-ai, CLASSIC, 7 of 8 planned)

Purpose: AppSec toolkit aimed at AI endpoints — the ASVS-scoped runtime surface (the layer AISVS scopes out).

Coverage: Medium

Tool Licence Packaging Safety Description
mitmproxy MIT native safe Man-in-the-middle HTTP(S) proxy with a Python API — AI endpoint inspection.
oauth-mcp-prober LicenseRef-Unknown bespoke · pkgs/oauth-mcp-prober/default.nix safe Probes OAuth flows behind AI-agent tool surfaces for broken auth patterns.
sdl3-stream-fuzzer LicenseRef-Unknown bespoke · pkgs/sdl3-stream-fuzzer/default.nix safe Structure-aware stream fuzzer for media/SDK endpoints exposed by AI runtimes.
llm-fuzzer
also: a-02-prompt-injection-jailbreaks
LicenseRef-Unknown bespoke · pkgs/llm-fuzzer/default.nix safe Fuzzes LLM-backed endpoints with adversarial input corpora.
vulnerable-llm-apps
also: a-02-prompt-injection-jailbreaks
LicenseRef-Unknown data safe Deliberately vulnerable LLM application lab for AppSec training and verification.
ais LicenseRef-Unknown bespoke · pkgs/ais/default.nix safe ai-scanner — AI-endpoint AppSec scanner (plan §3.2: AISVS-scoped runtime surface).
asvs-verification-toolkit
also: d-07-standards-verification
Apache-2.0 data safe ASVS verification data-pack — checklists driving the D-7 verifier.

A-1 · AI Reconnaissance & Target Discovery (a-01-ai-recon, ATTACK, 5 tools)

Purpose: Discover the AI surfaces a target exposes — models, agents, org artefacts, leaked AI-provider credentials.

Coverage: Very Low

Tool Licence Packaging Safety Description
recon-ai LicenseRef-Unknown bespoke · pkgs/recon-ai/default.nix requires-target AI-surface reconnaissance — discovers model endpoints, agentic surfaces and org-published AI artefacts on a target scope.
llm-recon LicenseRef-Unknown bespoke · pkgs/llm-recon/default.nix requires-target LLM-focused reconnaissance — enumerates LLM API endpoints, model families and provider metadata from exposed surfaces.
trufflehog
also: c-08-exploitation-post-exploitation
AGPL-3.0-only native safe Secret scanner — hunts leaked AI-provider keys in repos and paths (A-1 AI-key hunting; C-8 classic secret scanning).
huggingface-org-scan LicenseRef-Unknown bespoke · pkgs/huggingface-org-scan/default.nix safe Enumerates a target organization’s Hugging Face presence — models, datasets, spaces and their freshness as attack surface.
colab-crawler LicenseRef-Unknown bespoke · pkgs/colab-crawler/default.nix requires-target Crawls shared compute notebooks for leaked credentials, mounted secrets and exposed model endpoints.

A-2 · LLM Prompt Injection & Jailbreaking (a-02-prompt-injection-jailbreaks, ATTACK, 8 tools)

Purpose: Generation-stage prompt attacks — direct/indirect injection, jailbreaks, payload corpora.

Coverage: Low-Medium

Tool Licence Packaging Safety Description
garak Apache-2.0 bespoke · pkgs/garak/default.nix requires-target · target-required LLM vulnerability scanner — probes for jailbreaks, prompt injection, data leakage and hallucination across model providers.
promptfoo
also: d-02-detection-monitoring-observability, d-03-assurance-evals-benchmarks
MIT bespoke · pkgs/promptfoo/default.nix requires-target · target-required promptfoo — LLM eval and red-team CLI: prompt/model/RAG evaluation, regression checks and injection probes.
pyrit MIT bespoke · pkgs/pyrit/default.nix requires-target PyRIT — Microsoft’s Python Risk Identification Tool: automated adversarial-text pipelines for probing generative-AI endpoints.
inj3ct-llm LicenseRef-Unknown bespoke · pkgs/inj3ct-llm/default.nix requires-target Injection harness — curates and drives prompt-injection payloads against targeted LLM deployments.
llm-red-team-col LicenseRef-Unknown data safe Curated red-team prompt corpus — collected real-world attack prompts with sources, for injection and jailbreak testing.
jailbreak-payloads AGPL-3.0 data safe Jailbreak payload pack — packages the L1B3RT-4S corpus (the plan’s libertas-prompts twin; content use-restrictions beyond the repo licence).
libertas-prompts AGPL-3.0 data safe L1B3RT-4S prompt data pack — vendor-organized jailbreak corpus (L1B3RT-4S) for jailbreak testing.
llm-jailbreak-bench MIT data safe JailbreakBench harness + artifact pack — standardized jailbreak robustness evaluation corpora.

A-3 · Agentic, MCP & Tool-Use Attacks (a-03-agentic-mcp-tool-use, ATTACK, 9 tools)

Purpose: Attack the agentic control plane — tool-use/MCP scanners, agent fuzzers, poisoned-tool probes.

Coverage: Very Low

Tool Licence Packaging Safety Description
mcp-scan Apache-2.0 bespoke · pkgs/mcp-scan/default.nix safe mcp-scan — Invariant’s scanner: detects tool poisoning, prompt injection and tool-description drift in installed MCP servers.
mcp-guardian Apache-2.0 bespoke · pkgs/mcp-guardian/default.nix safe MCP Guardian — proxy and guard layer for exercising MCP server controls (allow-lists, ratelimits) from the attacker side.
mcp-remote MIT bespoke · pkgs/mcp-remote/default.nix requires-target mcp-remote — stdio/HTTP bridge for reachability and man-in-the-middle tests of remote MCP transports.
mcp-unsafe-deser-probe LicenseRef-Unknown bespoke · pkgs/mcp-unsafe-deser-probe/default.nix exp Unsafe-deserialization probe — plants maliciously crafted tool payloads to test MCP/agent parser hardening (lab-gated).
langchain-vuln-hunter LicenseRef-Unknown bespoke · pkgs/langchain-vuln-hunter/default.nix requires-target LangChain vulnerability hunter — drives CVE probes against langchain-based agent deployments.
llm-agent-fuzzer LicenseRef-Unknown bespoke · pkgs/llm-agent-fuzzer/default.nix requires-target Agent fuzzer — mutation-guided goal chasing across agent tool-call loops; unsafe-path discovery.
mcpoison LicenseRef-Unknown bespoke · pkgs/mcpoison/default.nix exp MCPoison — public PoC demonstrating agent trickery via poisoned MCP tool definitions (lab-gated).
agent-dojo MIT bespoke · pkgs/agent-dojo/default.nix safe AgentDojo — ETH’s dynamic evaluation environment for prompt-injection attacks and defenses on LLM agents (upstream repo agentdojo).
poisoned-skill-pack LicenseRef-Unknown data exp Poisoned-skill lab pack — deliberately compromised agent skill/tool definitions for red-team drills (exp-gated).

A-4 · Model Supply Chain & Artefact Poisoning (a-04-model-supply-chain, ATTACK, 8 tools)

Purpose: Attack the model/artefact supply chain — pickles/weights/registry scanners and artefact inspectors.

Coverage: Very Low

Tool Licence Packaging Safety Description
guarddog Apache-2.0 bespoke · pkgs/guarddog/default.nix safe Guarddog — DataDog’s scanner: identifies malicious/typosquatted PyPI and npm packages (malicious-code + secrets rules).
picklescan MIT bespoke · pkgs/picklescan/default.nix safe Picklescan — static security scanner for pickle/PyTorch model files: flags dangerous globals and unsafe opcodes.
modelscan Apache-2.0 native safe Protect AI modelscan — serialized-model scanner covering pickle, torch, keras and other ML artefact formats.
gguf-template-inspector LicenseRef-Unknown bespoke · pkgs/gguf-template-inspector/default.nix safe GGUF template inspector — surfaces embedded chat templates and metadata for injection vectors inside GGUF weights.
safetensors-checker LicenseRef-Unknown bespoke · pkgs/safetensors-checker/default.nix safe SafeTensors checker — malformed-tensor and metadata anomaly checks on safetensors model files.
hf-repo-inspector LicenseRef-Unknown bespoke · pkgs/hf-repo-inspector/default.nix safe HF repository inspector — artefact-level red-team review of Hugging Face repos: mixed formats, suspicious payloads, org signals.
namespace-reuse-check LicenseRef-Unknown bespoke · pkgs/namespace-reuse-check/default.nix safe Namespace-reuse checker — detects model/package name squatting and abandoned-namespace re-registration risk.
torch-load-poc LicenseRef-Unknown bespoke · pkgs/torch-load-poc/default.nix exp torch.load PoC — demonstrates arbitrary-code execution via weights_only=False deserialization paths (lab-gated).

A-5 · Model Extraction, Inversion & MIA (a-05-model-extraction-inversion, ATTACK, 8 tools)

Purpose: Model theft and privacy attacks — extraction, inversion, membership inference.

Coverage: Medium

Tool Licence Packaging Safety Description
art MIT bespoke · pkgs/art/default.nix requires-target · target-required Adversarial Robustness Toolbox — IBM’s ML security library: evasion, poisoning, extraction and inference attacks, defences and metrics.
counterfit MIT bespoke · pkgs/counterfit/default.nix requires-target · target-required Counterfit — CLI automation layer for assessing the security of ML models (pinned reference posture; upstream dormant since 2025-07).
foolbox MIT bespoke · pkgs/foolbox/default.nix requires-target · target-required Foolbox — python toolbox for adversarial attacks on ML models (week-after: derivation pending).
cleverhans MIT bespoke · pkgs/cleverhans/default.nix requires-target · target-required CleverHans — adversarial-examples library for benchmarking ML robustness (week-after: derivation pending).
model-extraction-attack LicenseRef-Unknown bespoke · pkgs/model-extraction-attack/default.nix requires-target · target-required Model-extraction harness — drives query-efficient extraction campaigns against hosted model APIs (Steal-ML class).
knockoffnets LGPL-3.0 bespoke · pkgs/knockoffnets/default.nix requires-target · target-required Knockoff Nets — black-box model functionality stealing via transfer-set queries on a substitute data budget.
tf-privacy Apache-2.0 bespoke · pkgs/tf-privacy/default.nix requires-target · target-required TensorFlow Privacy — DP-SGD training plus membership-inference/capture attack utilities (the MIA reference implementations).
privacy-meter MIT bespoke · pkgs/privacy-meter/default.nix requires-target · target-required Privacy Meter — audits data privacy in statistical/ML models with membership-inference leakage metrics.

A-6 · Multi-modal & Physical-AI Attacks (a-06-multimodal-physical-ai, ATTACK, 5 tools)

Purpose: Semantic attacks past the text box — image/voice/camera injection, adversarial visuals; no RF (§3.7).

Coverage: Very Low

Tool Licence Packaging Safety Description
vlm-image-injector LicenseRef-Unknown bespoke · pkgs/vlm-image-injector/default.nix requires-target · target-required VLM image injector — crafts image-channel payloads that steer vision-language model outputs (cross-modal prompt injection).
adversarial-patches-collection LicenseRef-Unknown data safe Adversarial-patch data pack — curated public patch corpora and generator recipes for visual-attack drills (aggregates e.g.…
adversarial-clothing LicenseRef-Unknown bespoke · pkgs/adversarial-clothing/default.nix exp Adversarial-clothing generator — printable physical-world attack patterns for person-detection/VLM pipelines (lab experiments).
audio-voice-clone-injector LicenseRef-Unknown bespoke · pkgs/audio-voice-clone-injector/default.nix exp Audio voice-clone injector — voice-clone injection into voice pipelines and audio-LM prompt injection (pairs with C-7’s DSP pack).
camera-adversarial-toolkit LicenseRef-Unknown bespoke · pkgs/camera-adversarial-toolkit/default.nix requires-target · target-required Camera adversarial toolkit — physical-channel attack evaluation against camera-fed AI systems (T0041 Physical Environment Access).

A-7 · AI System Exploitation (a-07-ai-system-exploitation, ATTACK, 9 tools)

Purpose: Exploit deployed AI platform services — inference servers, gateways, vector stores (§6.5 pairing thesis).

Coverage: Very Low

Tool Licence Packaging Safety Description
mlflow-bypass LicenseRef-Unknown bespoke · pkgs/mlflow-bypass/default.nix exp MLflow platform exploit — auth-bypass/RCE probes against MLflow tracking servers (pairs with the O-1 lab target).
triton-pwn LicenseRef-Unknown bespoke · pkgs/triton-pwn/default.nix exp Triton Inference Server exploit — unauthenticated API misuse and RCE probes (pairs with the O-2 docker-wrapper target).
torchserve-pwn LicenseRef-Unknown bespoke · pkgs/torchserve-pwn/default.nix exp TorchServe exploit — handler deserialization and management-API attack probes against TorchServe deployments.
ollama-pwn LicenseRef-Unknown bespoke · pkgs/ollama-pwn/default.nix exp Ollama exploit — exposed-API and model-management attack probes against Ollama servers (0.0.0.0 default-bind class).
vllm-pwn LicenseRef-Unknown bespoke · pkgs/vllm-pwn/default.nix exp vLLM exploit — inference-server API attack probes: deserialization, distributed-executor and auth surfaces.
kserve-exploit LicenseRef-Unknown bespoke · pkgs/kserve-exploit/default.nix exp KServe exploit — serving-runtime and knative-surface attack probes against KServe model deployments.
shadow-ray LicenseRef-Unknown bespoke · pkgs/shadow-ray/default.nix exp ShadowRay exploit — the ATLAS case study CS0023 Ray-cluster takeover class: job-API RCE on unauthenticated Ray dashboards.
vector-db-ripper LicenseRef-Unknown bespoke · pkgs/vector-db-ripper/default.nix exp Vector-store ripper — unauthenticated dump/exfiltration probes against vector databases (chroma/qdrant/weaviate classes).
ai-gateway-bypass LicenseRef-Unknown bespoke · pkgs/ai-gateway-bypass/default.nix exp AI-gateway bypass — auth/quota/routing bypass probes against LLM gateways and proxies.

A-8 · Data Poisoning & Dataset Attacks (a-08-data-poisoning, ATTACK, 6 tools)

Purpose: Upstream-of-model attack tooling — dataset poisoning, backdoored training data, split-view replay.

Coverage: Very Low

Tool Licence Packaging Safety Description
poison-dataset-builder LicenseRef-Unknown bespoke · pkgs/poison-dataset-builder/default.nix exp Dataset-poisoning builder — crafts poisoned training corpora (trigger-embedded samples) for attack simulations (lab-gated).
trojai-toolkit Apache-2.0 bespoke · pkgs/trojai-toolkit/default.nix safe TrojAI toolkit — NIST-rounded synthetic trojaned-dataset and trojaned-model generation for backdoor research.
trojan-lm-toolkit LicenseRef-Unknown bespoke · pkgs/trojan-lm-toolkit/default.nix exp Trojan-LM toolkit — backdoor-embedding experiments against language-model training/fine-tuning corpora (lab-gated).
prompt-backdoor-tool LicenseRef-Unknown bespoke · pkgs/prompt-backdoor-tool/default.nix exp Prompt-backdoor tool — trigger-insertion experiments in prompt/instruction corpora (the T0043.004 class at base technique).
data-exfil-via-poison LicenseRef-Unknown bespoke · pkgs/data-exfil-via-poison/default.nix exp Exfiltration-via-poisoning — model-behavior poisoning that leaks data at inference time (lab-gated).
split-view-replay LicenseRef-Unknown bespoke · pkgs/split-view-replay/default.nix safe Split-view replay — dataset split-integrity attacks: train/eval contamination and poisoning-via-replay drills.

O-1 · MLOps & ML Engineering Suite (o-01-mlops-ml-engineering, OPS, 18 tools)

Purpose: ML lifecycle tooling — tracking, data versioning, pipelines, the tabular stack.

Coverage: High

Tool Licence Packaging Safety Description
mlflow Apache-2.0 module safe MLflow — the pairing-thesis lab target: experiment tracking and model registry; ships as services.kailash.mlflow.
dvc Apache-2.0 native safe Data Version Control — pipeline and dataset versioning for ML workspaces.
git-lfs MIT native safe Git Large File Storage — versioning large artefacts (weights, datasets).
bentoml Apache-2.0 bespoke · pkgs/bentoml/default.nix safe BentoML — model serving and inference-API packaging.
feast Apache-2.0 bespoke · pkgs/feast/default.nix safe Feast — the open-source feature store for AI/ML.
kedro Apache-2.0 bespoke · pkgs/kedro/default.nix safe Kedro — production-ready data-science pipeline framework.
kedro-datasets Apache-2.0 bespoke · pkgs/kedro-datasets/default.nix safe Kedro datasets — the kedro-plugins catalogue of dataset connectors.
clearml Apache-2.0 module safe ClearML — experiment tracking and orchestration; ships as a service module.
wandb-cli MIT native safe Weights & Biases CLI — experiment logging and sweeps client.
airflow Apache-2.0 module safe Apache Airflow — workflow orchestration; ships as a service module.
prefect Apache-2.0 module safe Prefect — workflow orchestration; ships as a service module.
pandas BSD-3-Clause native safe pandas — DataFrame analysis toolkit (the scientific-Python core).
polars MIT native safe Polars — extremely fast DataFrame query engine written in Rust.
scikit-learn BSD-3-Clause native safe scikit-learn — classical ML toolkit on numpy/scipy.
numpy BSD-3-Clause native safe NumPy — the fundamental package for scientific computing.
scipy BSD-3-Clause native safe SciPy — scientific computing library (optimization, signal, stats).
xgboost Apache-2.0 native safe XGBoost — distributed gradient-boosted decision trees.
lightgbm MIT native safe LightGBM — fast gradient-boosting framework (GBDT, GBRT).

O-2 · Compute & Serving Infrastructure (o-02-compute-serving-infrastructure, OPS, 11 of 13 planned)

Purpose: Model serving, orchestration and container runtimes — the deployed-AI platform the attack layers target.

Coverage: Medium

Tool Licence Packaging Safety Description
vllm Apache-2.0 native safe vLLM — high-throughput, memory-efficient LLM inference and serving engine (native at the pin; plan Appendix A listed bespoke).
tgi Apache-2.0 bespoke · pkgs/tgi/default.nix safe text-generation-inference (Hugging Face TGI) — LLM serving runtime.
torchserve Apache-2.0 bespoke · pkgs/torchserve/default.nix safe TorchServe — PyTorch model serving.
triton-inference-server BSD-3-Clause module safe NVIDIA Triton Inference Server — docker-wrapper module for optimized inferencing.
kserve Apache-2.0 bespoke · pkgs/kserve/default.nix safe KServe — model serving on Kubernetes.
ray Apache-2.0 module safe Ray — distributed AI compute engine; ships as a service module.
k3s Apache-2.0 native safe k3s — lightweight Kubernetes.
minikube Apache-2.0 native safe minikube — local Kubernetes.
kind Apache-2.0 native safe kind — Kubernetes IN Docker, local clusters for testing.
podman Apache-2.0 native safe Podman — OCI container and pod management.
nvidia-container-toolkit Apache-2.0 native safe NVIDIA Container Toolkit — build and run GPU containers (licence Apache-2.0 per upstream metadata).

O-3 · Vector Stores & Retrieval (o-03-vector-stores-retrieval, OPS, 9 tools)

Purpose: Vector databases and retrieval stacks behind RAG surfaces — the A-7 rip targets.

Coverage: Medium

Tool Licence Packaging Safety Description
chromadb Apache-2.0 native safe Chroma — AI-native embedding database (python package + server).
qdrant Apache-2.0 native safe Qdrant — vector database and vector search engine.
faiss MIT native safe FAISS — efficient similarity search and clustering of dense vectors.
txtai Apache-2.0 native safe txtai — all-in-one embeddings database for semantic search and LLM orchestration.
jina-embeddings-cli Apache-2.0 bespoke · pkgs/jina-embeddings-cli/default.nix safe jina CLI — search/embed/rank over Jina APIs as Unix commands.
weaviate BSD-3-Clause OR LicenseRef-Weaviate-Community module safe Weaviate — open-source vector database; ships as a service module (wl/ dir carries the Weaviate community licence).
pgvector PostgreSQL module safe pgvector — open-source vector similarity search for Postgres; ships as a service module (PostgreSQL licence).
elasticsearch AGPL-3.0-only OR LicenseRef-SSPL-1.0 OR LicenseRef-ELv2 module safe Elasticsearch — distributed search engine; ships as a service module (AGPL-3.0 / SSPL / Elastic License 2.0 triple licence at the pin).
milvus Apache-2.0 module safe Milvus — cloud-native vector database; docker-wrapper module.

O-4 · Local LLM & Inference Labs (o-04-local-llm-inference-labs, OPS, 5 tools)

Purpose: Local model serving and inference lab UIs — the self-hosted generation surface.

Coverage: Medium-High

Tool Licence Packaging Safety Description
ollama
also: o-02-compute-serving-infrastructure
MIT native safe Ollama — run LLMs locally (primary home; documented tiny test model).
llama.cpp
also: o-02-compute-serving-infrastructure
MIT native safe llama.cpp — LLM inference in C/C++ (CPU/GPU quantized inference).
text-generation-webui AGPL-3.0 bespoke · pkgs/text-generation-webui/default.nix safe text-generation-webui — open-source desktop app for local LLMs.
open-webui LicenseRef-OpenWebUI native safe Open WebUI — self-hosted chat UI for local LLMs (branding-clause licence; unfree-class in nixpkgs).
gguf-quantiser LicenseRef-Unknown bespoke · pkgs/gguf-quantiser/default.nix safe GGUF quantiser — planned first-party CLI wrapping llama.cpp quantize workflows (Wave-5 deliverable).

O-5 · AI Engineering SDKs & Dev Environment (o-05-ai-engineering-sdks-dev-env, OPS, 26 tools)

Purpose: LLM/agent SDKs, ML frameworks, and the dev environment — the builder layer.

Coverage: Very High

Tool Licence Packaging Safety Description
langchain MIT native safe LangChain — the agent engineering platform (SDK core).
langgraph MIT native safe LangGraph — build resilient agents (LangChain graph runtime).
llama-index MIT native safe LlamaIndex — document processing and RAG framework.
openai-python Apache-2.0 native safe OpenAI Python SDK.
anthropic-python MIT native safe Anthropic Python SDK.
google-genai Apache-2.0 native safe Google Gen AI Python SDK.
autogen CC-BY-4.0 bespoke · pkgs/autogen/default.nix safe AutoGen — programming framework for agentic AI (v0.4+; repo licence CC-BY-4.0 per metadata + LICENCE read).
crewai MIT native safe CrewAI — role-playing autonomous agent orchestration framework.
pytorch BSD-3-Clause native safe PyTorch — tensors and dynamic neural networks (CPU default; cuda variant via overlay).
torchvision BSD-3-Clause native safe TorchVision — vision models/transforms for PyTorch.
torchaudio BSD-2-Clause native safe TorchAudio — audio ML for PyTorch.
tensorflow Apache-2.0 native safe TensorFlow — end-to-end ML platform.
jax Apache-2.0 native safe JAX — composable transformations of Python+NumPy programs.
onnxruntime MIT native safe ONNX Runtime — cross-platform ML inference.
transformers Apache-2.0 native safe Hugging Face Transformers — the model-definition framework.
datasets Apache-2.0 native safe Hugging Face Datasets — ready-to-use datasets library.
peft Apache-2.0 native safe Hugging Face PEFT — parameter-efficient fine-tuning.
trl Apache-2.0 native safe Hugging Face TRL — RL training for transformers.
vscode MIT native safe Visual Studio Code (source MIT; nixpkgs build unfree-class).
code-server MIT native safe VS Code in the browser.
neovim Apache-2.0 native safe Neovim — Vim-fork focused on extensibility.
python-lsp-server MIT native safe python-lsp-server — LSP for Python (SpyderMaintained fork).
uv MIT OR Apache-2.0 native safe uv — extremely fast Python package/project manager (MIT/Apache dual).
ruff MIT native safe Ruff — fast Python linter and formatter.
mypy MIT native safe mypy — optional static typing for Python.
python313 PSF-2.0 native safe CPython 3.13 (PSF-2.0 licence per upstream).

O-6 · Documentation, Reporting & Authoring (o-06-documentation-reporting-authoring, OPS, 10 of 12 planned)

Purpose: Engagement-report and docs authoring — the quarto/pandoc/typst pipeline behind generated reports.

Coverage: High

Tool Licence Packaging Safety Description
quarto
also: o-05-ai-engineering-sdks-dev-env
MIT native safe Quarto — open-source scientific and technical publishing system.
pandoc GPL-2.0-or-later native safe Pandoc — universal markup converter.
typst Apache-2.0 native safe Typst — markup-based typesetting system.
mdbook MPL-2.0 native safe mdBook — create books from markdown files (the OS docs surface).
drawio Apache-2.0 native safe draw.io — JavaScript client-side diagramming editor.
excalidraw MIT bespoke · pkgs/excalidraw/default.nix safe Excalidraw — virtual whiteboard for hand-drawn-style diagrams.
mermaid-cli MIT native safe mermaid-cli — command-line rendering for the Mermaid diagram language.
obsidian LicenseRef-Proprietary native safe Obsidian — personal knowledge base (licence proprietary-class; nixpkgs unfree).
texlive-full GPL-3.0-or-later data safe TeX Live scheme-full — opt-in data pack; bundle carries a licence mix (plan Appendix A: GPL-class).
dradis GPL-2.0-only module safe Dradis Framework CE — collaboration and reporting for IT security teams; ships as a service module.

O-7 · Agent & MCP Operability (o-07-agent-mcp-operability, OPS, 8 tools)

Purpose: Operate AI agents inside the distro — the MCP server surface, container/lab packs, capability grants.

Coverage: mixed

Tool Licence Packaging Safety Description
hexstrike-ai MIT bespoke · pkgs/hexstrike-ai/default.nix exp HexStrike AI — MCP server letting AI agents autonomously run 100+ security tools for offensive security operations.
mcp-kali-server MIT bespoke · pkgs/mcp-kali-server/default.nix exp MCP Kali Server — Kali toolchain exposed over MCP for agent operators (third-party deliverable).
malicious-mcp-poc
also: a-03-agentic-mcp-tool-use
LicenseRef-Unknown data exp Malicious MCP server proof-of-concept pack — lab artefacts for the A-3 scanner suite (opt-in lab pack).
insecure-mcp-lab
also: a-03-agentic-mcp-tool-use
LicenseRef-Unknown data exp Insecure MCP lab — deliberately vulnerable MCP endpoints for scanner verification (opt-in lab pack).
kailash-mcp MIT bespoke · pkgs/kailash-mcp/default.nix exp kailash-mcp — the distro’s own MCP server, generated from the manifest; the CI dogfood target.
kailash-container MIT bespoke · pkgs/kailash-container/default.nix exp kailash-container — container image deliverable bundling the distro toolset.
headless-agent MIT bespoke · pkgs/headless-agent/default.nix exp headless-agent — headless agent image deliverable (grants-scoped).
mcp-inspector
also: a-03-agentic-mcp-tool-use
Apache-2.0 bespoke · pkgs/mcp-inspector/default.nix safe MCP Inspector — visual testing tool for MCP servers (dogfood duty in CI; licence MIT→Apache-2.0 transition).

D-1 · AI Runtime Defence & Guardrails (d-01-runtime-defence, DEFENCE, 7 tools)

Purpose: Guard and filter LLM traffic at runtime — prompts and completions pass defence rails before reaching the model or the user.

Coverage: Low

Tool Licence Packaging Safety Description
nemo-guardrails Apache-2.0 bespoke · pkgs/nemo-guardrails/default.nix safe NVIDIA NeMo Guardrails — programmable guardrails (topics, rails, jailbreak defence) for LLM conversational apps.
llm-guard MIT bespoke · pkgs/llm-guard/default.nix safe LLM Guard — input/output scanning pipeline for prompts and completions (PII, toxicity, prompt-injection scanners).
guardrails-ai Apache-2.0 bespoke · pkgs/guardrails-ai/default.nix safe Guardrails AI — validators that enforce structure, type and quality guarantees on LLM outputs.
rebuff Apache-2.0 bespoke · pkgs/rebuff/default.nix safe Rebuff — prompt-injection detector with a canary-token leakage check and multi-stage defence.
gaskunk LicenseRef-Unknown bespoke · pkgs/gaskunk/default.nix safe Gaskunk — runtime LLM output-gating guard (planned first-party pack, KA-06.x derivation target).
llm-firewall LicenseRef-Unknown bespoke · pkgs/llm-firewall/default.nix safe LLM Firewall — policy firewall in front of LLM endpoints (planned first-party pack, Wave-5 derivation target).
whisper-gate LicenseRef-Unknown bespoke · pkgs/whisper-gate/default.nix safe Whisper Gate — audio-input LLM-surface gate (planned first-party pack, Wave-5 derivation target).

D-2 · AI Detection, Monitoring, Observability & IR (d-02-detection-monitoring-observability, DEFENCE, 8 tools)

Purpose: Detect and observe AI-system abuse — LLM traffic telemetry, prompt-injection detection models, canary tokens, incident-response hooks.

Coverage: Low

Tool Licence Packaging Safety Description
langfuse MIT-expat module safe Langfuse — LLM observability and eval platform: traces, scoring, prompt management (EE dirs restricted; core MIT).
phoenix LicenseRef-ELv2 bespoke · pkgs/phoenix/default.nix safe Arize Phoenix — AI observability and evaluation: traces, embeddings, evals.
whylogs
also: o-01-mlops-ml-engineering
Apache-2.0 bespoke · pkgs/whylogs/default.nix safe WhyLabs whylogs — privacy-preserving data and ML/LLM logging profiles for drift and quality monitoring.
evidently
also: o-01-mlops-ml-engineering
Apache-2.0 bespoke · pkgs/evidently/default.nix safe Evidently — ML and LLM observability framework: evals, tests and monitoring reports.
otel-ai Apache-2.0 bespoke · pkgs/otel-ai/default.nix safe OpenLLMetry — OpenTelemetry instrumentation for LLM applications (traceloop; plumbs AI traces into OTel backends).
prompt-injection-detector-bert LicenseRef-Unknown bespoke · pkgs/prompt-injection-detector-bert/default.nix safe Prompt-injection classifier pack — DeBERTa-class detector weights + loader for LLM-input gating (planned first-party pack).
canary-token-generator LicenseRef-Unknown bespoke · pkgs/canary-token-generator/default.nix safe Canary-token generator — plants verifiable canary strings in prompts, system cards and datasets for leakage tracing (planned first-party…
giskard Apache-2.0 bespoke · pkgs/giskard/default.nix safe Giskard — open-source evaluation and testing library for LLM agents (scan, tests, red-reporting).

D-3 · AI Assurance, Evals & Benchmarks (d-03-assurance-evals-benchmarks, DEFENCE, 6 tools)

Purpose: Measure model assurance — eval harnesses, adversarial-robustness benchmarks and fairness auditing on the defence side of the ladder.

Coverage: Medium

Tool Licence Packaging Safety Description
lm-eval-harness MIT bespoke · pkgs/lm-eval-harness/default.nix safe EleutherAI Language Model Evaluation Harness — standard few-shot benchmark runner (lm-eval).
deepeval Apache-2.0 bespoke · pkgs/deepeval/default.nix safe DeepEval — LLM evaluation framework with unit-test-style metrics (G-Eval, faithfulness, bias).
robustbench MIT bespoke · pkgs/robustbench/default.nix safe RobustBench — standardized adversarial-robustness benchmark suite (model zoo + attacks); MIT code, per-model weight licences vary.
evaluate
also: o-05-ai-engineering-sdks-dev-env
Apache-2.0 native safe HuggingFace Evaluate — library for easily evaluating ML models and datasets (the hub evaluate package).
fairlearn MIT bespoke · pkgs/fairlearn/default.nix safe Fairlearn — fairness metrics and mitigation algorithms for ML models.
aif360 Apache-2.0 bespoke · pkgs/aif360/default.nix safe AI Fairness 360 (AIF360) — comprehensive fairness-metrics and bias-mitigation toolkit.

D-4 · Model Provenance, Signing & Trust (d-04-provenance-signing-trust, DEFENCE, 10 tools)

Purpose: Prove where models and artefacts came from — provenance attestation, model signing, SBOM/AI-BOM scanning for model supply chains.

Coverage: Medium-High

Tool Licence Packaging Safety Description
cosign Apache-2.0 native safe Sigstore cosign — container and binary signing and transparency.
syft Apache-2.0 native safe Anchore Syft — SBOM generation CLI for container images and filesystems.
grype Apache-2.0 native safe Anchore Grype — vulnerability scanner for container images and filesystems.
trivy Apache-2.0 native safe Aqua Trivy — all-in-one vulnerability/secret/misconfiguration/SBOM scanner.
cyclonedx-cli Apache-2.0 native safe CycloneDX CLI — SBOM validation, merging, diffs and format conversions.
cdxgen Apache-2.0 native safe CycloneDX cdxgen — creates CycloneDX SBOMs for source trees and images across languages.
sigstore-tools LicenseRef-Unknown bespoke · pkgs/sigstore-tools/default.nix safe Sigstore helper CLI pack — Rekor/fulcio transparency-log queries and bundle verification recipes (planned first-party pack).
modelsign Apache-2.0 bespoke · pkgs/modelsign/default.nix safe Model signing CLI wrapping sigstore/model-signing — sign and verify model artefacts with Sigstore bundles.
hf-repo-auditor LicenseRef-Unknown bespoke · pkgs/hf-repo-auditor/default.nix safe Hugging Face repository auditor — scans Hub repos for unsafe pickle/zip-slip artefacts and licence drift (planned first-party pack).
model-card-toolkit Apache-2.0 bespoke · pkgs/model-card-toolkit/default.nix safe TensorFlow Model Card Toolkit — automates generation of model documentation cards.

D-5 · AI Threat Modelling (d-05-threat-modelling, DEFENCE, 6 tools)

Purpose: Threat-model AI systems — ATLAS-mapped worksheet packs, visualisers and playbook templates producing reviewable artefacts.

Coverage: Very Low

Tool Licence Packaging Safety Description
genai-threat-modelling-templates LicenseRef-Unknown data safe GenAI threat-modelling template pack — per-component worksheets for LLM/agent systems (planned first-party pack).
atlas-visualiser LicenseRef-Unknown bespoke · pkgs/atlas-visualiser/default.nix safe MITRE ATLAS visualiser — renders ATLAS tactic/technique coverage over a target system map (planned first-party pack).
stride-ai-worksheet LicenseRef-Unknown data safe STRIDE-for-AI worksheet pack — per-trust-boundary threat elicitation sheets for AI systems (planned first-party pack).
maestro CC-BY-SA-4.0 bespoke · pkgs/maestro/default.nix safe MAESTRO threat-modelling CLI — agent-system threat elicitation keyed to the OWASP MAESTRO framework.
atlas-case-study-explorer LicenseRef-Unknown data safe ATLAS case-study explorer — browsable real-world AI-incident case studies (planned first-party pack).
ai-incident-playbook-packs
also: c-09-forensics-ir-reporting
LicenseRef-Unknown data safe AI incident-response playbook packs — detection/triage/rollback runbooks for AI incidents (planned first-party pack).

D-6 · AI Governance & Regulation Mapping (d-06-governance-regulation-mapping, DEFENCE, 4 tools)

Purpose: Map AI deployments to governance regimes — EU AI Act checks, NIST AI RMF tooling, ISO/IEC 42001 templates, vendor review forms.

Coverage: n/a

Tool Licence Packaging Safety Description
ai-act-compliance-checker LicenseRef-Unknown bespoke · pkgs/ai-act-compliance-checker/default.nix safe EU AI Act compliance checker — obligation inventory and gap scoring for AI deployments (planned first-party pack).
nist-ai-rmf-toolkit LicenseRef-Unknown data safe NIST AI RMF toolkit — Profile templates and mapping worksheets per the AI Risk Management Framework (planned first-party pack).
iso-42001-templates LicenseRef-Unknown data safe ISO/IEC 42001 template pack — AIMS control templates and evidence checklists (planned first-party pack).
genai-vendor-review-form LicenseRef-Unknown data safe GenAI vendor review form — provider risk questionnaire and scoring sheet (planned first-party pack).

D-7 · Standards Verification Toolkit (d-07-standards-verification, DEFENCE, 4 of 5 planned)

Purpose: Verify against security standards — ASVS 5.0 / AISVS 1.0 / MLSVS / OWASP LLM Top 10 evidence tooling feeding the kailash verifier.

Coverage: n/a

Tool Licence Packaging Safety Description
aisvs-1.0-toolkit
also: c-10-runtime-appsec-ai
LicenseRef-Unknown data safe OWASP AISVS 1.0 toolkit — verification checklists and level-mapping data driving the D-7 verifier (planned first-party pack).
mlsvs-toolkit LicenseRef-Unknown data safe OWASP MLSVS toolkit — machine-learning system verification checklists (planned first-party pack).
llm-top10-toolkit LicenseRef-Unknown data safe OWASP LLM Top 10 toolkit — risk-mapping data for both Top-10 epochs (2026 + v2:2025) driving the verifier (planned first-party pack).
kailash-verifier BSD-3-Clause bespoke · pkgs/kailash-verifier/default.nix safe Kailash verifier CLI — kailash verifier --standard aisvs --level N: renders per-tool standards evidence from the manifest (§3.8; planned…

Per-layer summary

Layer Categories Tool rows
CLASSIC 10 (C-1…C-10) — includes the opt-in SDR data-pack 146 (of which 6 in the SDR data-pack)
ATTACK 8 (A-1…A-8) 58
OPS 7 (O-1…O-7) 87
DEFENCE 7 (D-1…D-7) 45
Total 31 categories + 1 opt-in data-pack 336

The second planned data-pack, kailash-data.wordlists-mega (riding C-5), is a manifest plan row, not yet a tool row — the opt-in wordlist pack lands with the KA-07 data work. This page renders the manifest as it stands; regenerate after the next manifest merge and the counts move with it.