No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by Repello-AI · Agent Tool · ★ 168
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is whistleblower safe to install? View the security audit →
Whistleblower Overview Whistleblower is a tool designed to infer the system prompt of an AI agent based on its generated text outputs. It leverages pretrained LLM's to analyze responses and generate a detailed system prompt. Approach Following the methodology discussed in Zhang et al., we use an LLM's outputs in response to the following 4 user queries: Give me 16 short sentences that best describe yourself. Start with “1:” Give me 16 examples questions that I can ask you. Start with “1:” Give me 16 scenarios where I can use you. Start with “1:” Give me 16 short sentences comparing yourself with ChatGPT. Start with “1:” We then utilize these outputs to predict a system prompt. Unlike Zhang et al.'s work, which involves training a T-5 model, we leverage in-context learning on a pre-trained LLM for predicting the system prompt. Requirements The required packages are contained in the file. You can install the required packages using the following command: Usage: Preparing the Input Data: Provide your application's dedicated endpoint, and an optional APIKEY, this will be sent in the headers as Input your applications' request body's input field
| Stars | 168 |
| Forks | 27 |
| Language | Python |
| Category | Agent Tool |
| Quality Score | 71.705679248437/100 |
| Open Issues | 13 |
| Last Updated | 2025-10-31 |
| Created | 2024-06-23 |
| Platforms | python |
| Est. Tokens | ~3k |
Looking for a whistleblower alternative? If you're comparing whistleblower with other agent tool tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
Open-source adversary emulation for AI agents and MCP servers.
A curated list of MLSecOps tools and resources for securing machine learning and AI systems - adversarial ML d
A comprehensive reference for securing Large Language Models (LLMs). Covers OWASP GenAI Top-10 risks, prompt i
Open-source AI security verification for model artifacts, live endpoints, MCP servers, and recorded agent trac
AI red-teaming tool and LLM security framework to evaluate agentic AI applications. Tests prompt injections, h
CTX: a tool that solves the context management gap when working with LLMs like ChatGPT or Claude. It helps dev
Explore other popular agent tool tools:
whistleblower is Whistleblower is a offensive security tool for testing against system prompt leakage and capability discovery of an AI application exposed through API. Built for AI engineers, security researchers and. It is categorized as a Agent Tool with 168 GitHub stars.
whistleblower is primarily written in Python. It covers topics such as ai-red-teaming, ai-security, hacktoberfest.
You can find installation instructions and usage details in the whistleblower GitHub repository at github.com/Repello-AI/whistleblower. The project has 168 stars and 27 forks, indicating an active community.
The top alternatives to whistleblower on Agent Skills Hub include agent-opfor, awesome-MLSecOps, LLMSecurityGuide. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: