AppSecNews
AI Security Open source Emerging

Augustus

by Praetorian

Open source prompt injection testing tool released by Praetorian for probing LLM applications with adversarial inputs.

Visit praetorian.com (leaves AppSecNews, opens in a new tab) Leaves AppSecNews for the vendor's own site.

No endorsements yet

Run Augustus in production? A named recommendation helps the next team shortlisting it.

Recommend this tool

Endorsers verify their identity through LinkedIn. Titles and companies are self declared, shown as they were when each person signed, and reviewed by an editor before anything is published. Endorsements are never paid for.

What we still need to verify : 5 points in this profile are not yet confirmed against vendor documentation.
  • Core capabilities and attack technique coverage: not confirmed, this profile is written from limited knowledge
  • Implementation language, installation method and runtime requirements: unconfirmed
  • Supported model providers and integration points: unconfirmed
  • Whether the project is actively maintained: confirm before recommending
  • Output format and CI usability: unconfirmed

Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.

What it does

Augustus is an open source prompt injection testing tool published by Praetorian, a security consultancy, and released alongside a write up of the research behind it. It belongs to the category of offensive testing harnesses for language model applications: tooling that sends crafted inputs to a target, observes the response, and reports where the target's instructions were displaced by attacker supplied content.

I do not have reliable detail on its specific technique catalog, its interface, or its provider support, and the rules of this catalog are that I say so rather than fill the gap with plausible sounding capability claims. What can be said with confidence is the general shape of the problem it addresses. Prompt injection is not a bug to be patched in a model, it is a structural consequence of mixing trusted instructions with untrusted content in a single context window. Testing for it means establishing whether your specific system prompt, retrieval sources and tool permissions can be turned against you, which is application specific work that generic model benchmarks do not answer.

Where it fits

Tools of this kind run against a deployed instance of an application, typically in staging, driven by a security engineer or a consultant during an assessment rather than by a developer on every commit. They require a reachable endpoint, credentials if the application is authenticated, and a clear statement of what a successful injection would mean in your system: data exfiltration from a retrieval index, an unauthorized tool call, or an instruction override that changes downstream behavior.

Strengths

  • Released with public research rather than as a product, so the reasoning behind it is available to read and evaluate.
  • Open source, so it can be inspected, extended and run entirely within your own network.
  • Backed by a consultancy that does this work in engagements, which usually means the techniques reflect what actually succeeds in the field.

Limitations

  • Capability detail here is unverified. Read the project documentation before planning any work around it.
  • Tools released alongside research posts vary widely in ongoing maintenance, and an unmaintained injection tester degrades quickly as models and defenses change.
  • Any prompt injection tester proves the presence of a weakness, never its absence. A clean run is weak evidence.

Who it suits

Security engineers doing hands on assessment of LLM applications who are comfortable evaluating a research tool on its merits. Teams wanting a supported, continuously updated red teaming capability should look at maintained frameworks or commercial platforms instead.

Used Augustus? Recommend it under your own name and title.

Recommend this tool