> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://hiddenlayer.ferndocs.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://hiddenlayer.ferndocs.com/_mcp/server.

# Red Team Prompt Sets

Manage reusable prompt sets for testing.

![Log In Page](/_fern-img/a3262f4b65f918a02e93c22a68cfc3c3781c67f61a12db147d8ccb392ee154b0.webp)

## Create Prompt Set

1. In the HiddenLayer Console, select **Attack Simulation > Prompt Sets**.

2. Click **Create Prompt Set +**. The Create Prompt Set slide-out displays.

3. Enter a name for the prompt set.

4. Optionally, enter a description.

5. Upload a CSV file containing your prompt set. You can either drag-and-drop the file into the Upload Prompts field or click inside the field to open the file browser.

   * See [CSV File Example](#csv-file-example) for more information.

6. Click **Create Prompt Set**.

![Red Team Create Prompt Set](/_fern-img/122fc9f6a53a111cb1c9b47fe9c152f4a7c91c466e517425efd1c72b0ab2a5f0.webp)

### CSV File Example

CSV format requirements:

* Maximum file size: 10MB
* Maximum 1,000 prompts
* Single column: user prompts only
* Two columns: system prompts (optional), user prompts
* First row may contain headers: "system prompt, user prompt" or "user prompt"
* User prompts: max 20KB each
* System prompts: max 10KB each

#### Example Formats

**System Prompt and User Prompt with header**

```
system prompt, user prompt
this is the test system prompt, this is a test user prompt 1,
this is the test system prompt, this is a test user prompt 2
```

**System Prompt and User Prompt without header**

```
this is the test system prompt, this is a test user prompt 1,
this is the test system prompt, this is a test user prompt 2
```

**User Prompt with header**

```
user prompt
this is a test user prompt 1,
this is a test user prompt 2,
```

**User Prompt without header**

```
this is a test user prompt 1,
this is a test user prompt 2
```

## Best Practices

* **Compare Versions**: Run evaluations on both original and enhanced prompts to measure improvement.
* **Review Failed Attacks**: Understanding why attacks failed is as important as knowing which succeeded.
* **Use Appropriate Models**: Match the target model to what you're actually using in production.

## Run Evaluation

You can run an evaluation using any available prompt set.

1. In the Console, select **Attack Simulation > Prompt Sets**.
2. For the prompt set you want to use, click **Run Evaluation**. The Create Red Team Evaluation slide-out displays.
3. Enter a name for the evaluation.
4. Enter the target system prompt.
5. Select a target model.

   * Select a model that is similar to what you have in your environment to simulate the attacks against your system prompt.

> **Beta Models**
>
> Models marked with a `beta` designation may be subject to lower usage quotas, limited availability, or ongoing development changes. As a result, these models may exhibit unexpected results, reduced performance, or intermittent failures during testing. Users should account for these limitations when selecting beta models.

![Red Team Create Evaluation](/_fern-img/a5ae3d49ea0db6c784ec17b173a50264886bd44754460fd58fecc68584dae993.webp)

6. Optional: Click **Advanced Options** to expand the section.

   * Select a project to apply runtime rulesets to interaction tagging.

     * If no project is selected, the default project is used.

   * Select an execution strategy.

     * **Single**: Runs each technique once per objective.

     * **Random**: Runs all techniques plus N additional random techniques.

       * Select the number of additional random techniques.

       ![Red Team Evaluation Random](/_fern-img/5d307d9aa45ad5d90f72e3e01a1e43335ba4fadbb05bb23b0618429ab8b9f6e2.webp)

     * **Static prompt set**: Uses a predefined set of static prompts for evaluation.

       * Select the prompt set from the drop-down list.

       ![Red Team Evaluation Static Prompt Set](/_fern-img/71c3b66bacfe152a704a430a17dbadb656b462adbd8263bd25fce35a56ab9e65.webp)

   * Set the maximum number of conversation turns allowed per technique when attempting to achieve an objective. The minimum is one and the maximum is five.

     * The attack simulator will do multi-turn, trying to attack the target for N turns, and then go to the next session.
     * **Note**: If you selected `static_prompt_set`, then **Attacker Max Turns to Complete Objective** is not available.

   * Set the number of independent sessions to run for each technique. The minimum is one and the maximum is five.

     * This is the number of times you want to run the same technique or static prompt.

7. Click **Start Evaluation**.

8. When the evaluation completes, click the green arrow to view the results. See [Red Team Evaluation Summary](attack_simulation_red_teaming_evaluation_summary.md) for more information.

![Red Team Run Prompt Set](/_fern-img/274cef4f78ba6177e33b60f1ae6cf05d88c8a17e0e1ffb0320e660bfd310f810.webp)

## Pre-Configured Red Team Prompt Sets

Select a prompt set to run red team evaluations using pre-configured adversarial prompts designed to test your AI system's defenses.

To run an evaluation, see [Run Evaluation](#run-evaluation).

| Prompt Set                   | Description                                                                                                                                                                                                                                       |
| ---------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Do Anything Now APE          | Do Anything Now adversarial prompts for testing LLM safety and security.                                                                                                                                                                          |
| Financial Assistant Advanced | Financial Assistant Advanced is a prompt set scenario for testing a financial application against adversarial prompts. The system prompt for this scenario has been ran through the system prompt evaluation to make a more robust system prompt. |
| Financial Assistant Basic    | Financial Assistant Basic is a prompt set scenario for testing a financial assistant application against adversarial prompts. The system prompt ofr this scenario has not been ran through the system prompt evaluation.                          |