Risk Categories
Overview
The Confident AI SDK exposes every Risk Category method on the platform. This page documents how to call these methods in all supported languages. See the introduction to install the SDK and set your API key.
Methods
List Risk Categories
Lists the risk categories of a red teaming framework one page at a time, ordered by name. Each is returned with its selections counted; retrieve one by id to see which vulnerability types and attack methods it holds.
from confident_ai import ConfidentAI
client = ConfidentAI()
result = client.rt_frameworks.list_risk_categories(
rt_framework_id="<RT-FRAMEWORK-ID>",
page=1,
page_size=25,
)For async mode, call a_list_risk_categories and await it as shown below:
result = await client.rt_frameworks.a_list_risk_categories(...)Parameters
| Parameter | Type | Description |
|---|---|---|
rt_framework_id | str | Required. The id of the red teaming framework. |
page | Optional[int] | The page to return. Defaults to 1. |
page_size | Optional[int] | The number of results per page, at most 100. Defaults to 25. |
import { ConfidentAI } from "confident-ai";
const client = new ConfidentAI();
const result = await client.rtFrameworks.listRiskCategories(
"<RT-FRAMEWORK-ID>",
{ page: 1, pageSize: 25 },
);Parameters
| Parameter | Type | Description |
|---|---|---|
rtFrameworkId | string | Required. The id of the red teaming framework. |
page | number | The page to return. Defaults to 1. |
pageSize | number | The number of results per page, at most 100. Defaults to 25. |
Returns
This method returns an object of type RiskCategoryList.
Create Risk Category
Adds a risk category to a red teaming framework and returns its id. Send vulnerabilityTypeIds and attackMethodIds to fill it in the same call: a category with neither probes for nothing when the framework runs.
from confident_ai import ConfidentAI
client = ConfidentAI()
result = client.rt_frameworks.create_risk_category(
rt_framework_id="<RT-FRAMEWORK-ID>",
name="Data protection",
description="Risks around leaking data the model was given.",
vulnerability_type_ids=["<VULNERABILITY-TYPE-ID>"],
attack_method_ids=["<ATTACK-METHOD-ID>"],
vulnerability_id_to_priority_level={"<VULNERABILITY-ID>": 2},
)For async mode, call a_create_risk_category and await it as shown below:
result = await client.rt_frameworks.a_create_risk_category(...)Parameters
| Parameter | Type | Description |
|---|---|---|
rt_framework_id | str | Required. The id of the red teaming framework. |
name | str | Required. The name of the risk category, unique within the framework. |
description | Optional[str] | What this risk category covers. Send null to clear it. |
vulnerability_type_ids | Optional[List[str]] | The ids of the vulnerability types to probe for. The list replaces the category's current selection. |
attack_method_ids | Optional[List[str]] | The ids of the attack methods to probe with. The list replaces the category's current selection. |
vulnerability_id_to_priority_level | Optional[Dict[str, int]] | How much of the assessment each vulnerability gets, keyed by vulnerability id, from 0 to 3. Send null to clear every weight. |
import { ConfidentAI } from "confident-ai";
const client = new ConfidentAI();
const result = await client.rtFrameworks.createRiskCategory(
"<RT-FRAMEWORK-ID>",
"Data protection",
{
description: "Risks around leaking data the model was given.",
vulnerabilityTypeIds: ["<VULNERABILITY-TYPE-ID>"],
attackMethodIds: ["<ATTACK-METHOD-ID>"],
vulnerabilityIdToPriorityLevel: { <VULNERABILITY-ID>: 2 }
},
);Parameters
| Parameter | Type | Description |
|---|---|---|
rtFrameworkId | string | Required. The id of the red teaming framework. |
name | string | Required. The name of the risk category, unique within the framework. |
description | string | null | What this risk category covers. Send null to clear it. |
vulnerabilityTypeIds | string[] | The ids of the vulnerability types to probe for. The list replaces the category's current selection. |
attackMethodIds | string[] | The ids of the attack methods to probe with. The list replaces the category's current selection. |
vulnerabilityIdToPriorityLevel | Record<string, number> | null | How much of the assessment each vulnerability gets, keyed by vulnerability id, from 0 to 3. Send null to clear every weight. |
Returns
This method returns an object of type RiskCategoryRef.
Get Risk Category
Retrieves a risk category by id, with the vulnerability types it probes for, the attack methods it probes with, and how much of an assessment each vulnerability gets.
from confident_ai import ConfidentAI
client = ConfidentAI()
result = client.rt_frameworks.get_risk_category(
rt_framework_id="<RT-FRAMEWORK-ID>",
risk_category_id="<RISK-CATEGORY-ID>",
)For async mode, call a_get_risk_category and await it as shown below:
result = await client.rt_frameworks.a_get_risk_category(...)Parameters
| Parameter | Type | Description |
|---|---|---|
rt_framework_id | str | Required. The id of the red teaming framework the category belongs to. |
risk_category_id | str | Required. The id of the risk category. |
import { ConfidentAI } from "confident-ai";
const client = new ConfidentAI();
const result = await client.rtFrameworks.getRiskCategory(
"<RT-FRAMEWORK-ID>",
"<RISK-CATEGORY-ID>",
);Parameters
| Parameter | Type | Description |
|---|---|---|
rtFrameworkId | string | Required. The id of the red teaming framework the category belongs to. |
riskCategoryId | string | Required. The id of the risk category. |
Returns
This method returns an object of type RiskCategory.
Update Risk Category
Updates a risk category and returns it. Each list you send replaces the stored selection rather than adding to it, so send the complete set of vulnerability type ids or attack method ids you want the category to hold.
from confident_ai import ConfidentAI
client = ConfidentAI()
result = client.rt_frameworks.update_risk_category(
rt_framework_id="<RT-FRAMEWORK-ID>",
risk_category_id="<RISK-CATEGORY-ID>",
name="Data protection",
description="Risks around leaking data the model was given.",
vulnerability_type_ids=["<VULNERABILITY-TYPE-ID>"],
attack_method_ids=["<ATTACK-METHOD-ID>"],
vulnerability_id_to_priority_level={"<VULNERABILITY-ID>": 2},
)For async mode, call a_update_risk_category and await it as shown below:
result = await client.rt_frameworks.a_update_risk_category(...)Parameters
| Parameter | Type | Description |
|---|---|---|
rt_framework_id | str | Required. The id of the red teaming framework the category belongs to. |
risk_category_id | str | Required. The id of the risk category. |
name | Optional[str] | The name of the risk category, unique within the framework. |
description | Optional[str] | What this risk category covers. Send null to clear it. |
vulnerability_type_ids | Optional[List[str]] | The ids of the vulnerability types to probe for. The list replaces the category's current selection. |
attack_method_ids | Optional[List[str]] | The ids of the attack methods to probe with. The list replaces the category's current selection. |
vulnerability_id_to_priority_level | Optional[Dict[str, int]] | How much of the assessment each vulnerability gets, keyed by vulnerability id, from 0 to 3. Send null to clear every weight. |
import { ConfidentAI } from "confident-ai";
const client = new ConfidentAI();
const result = await client.rtFrameworks.updateRiskCategory(
"<RT-FRAMEWORK-ID>",
"<RISK-CATEGORY-ID>",
{
name: "Data protection",
description: "Risks around leaking data the model was given.",
vulnerabilityTypeIds: ["<VULNERABILITY-TYPE-ID>"],
attackMethodIds: ["<ATTACK-METHOD-ID>"],
vulnerabilityIdToPriorityLevel: { <VULNERABILITY-ID>: 2 }
},
);Parameters
| Parameter | Type | Description |
|---|---|---|
rtFrameworkId | string | Required. The id of the red teaming framework the category belongs to. |
riskCategoryId | string | Required. The id of the risk category. |
name | string | The name of the risk category, unique within the framework. |
description | string | null | What this risk category covers. Send null to clear it. |
vulnerabilityTypeIds | string[] | The ids of the vulnerability types to probe for. The list replaces the category's current selection. |
attackMethodIds | string[] | The ids of the attack methods to probe with. The list replaces the category's current selection. |
vulnerabilityIdToPriorityLevel | Record<string, number> | null | How much of the assessment each vulnerability gets, keyed by vulnerability id, from 0 to 3. Send null to clear every weight. |
Returns
This method returns an object of type RiskCategory.
Delete Risk Category
Permanently deletes a risk category from its framework, along with the selections and weights it held. The vulnerabilities and attack methods themselves are untouched.
from confident_ai import ConfidentAI
client = ConfidentAI()
result = client.rt_frameworks.delete_risk_category(
rt_framework_id="<RT-FRAMEWORK-ID>",
risk_category_id="<RISK-CATEGORY-ID>",
)For async mode, call a_delete_risk_category and await it as shown below:
result = await client.rt_frameworks.a_delete_risk_category(...)Parameters
| Parameter | Type | Description |
|---|---|---|
rt_framework_id | str | Required. The id of the red teaming framework the category belongs to. |
risk_category_id | str | Required. The id of the risk category. |
import { ConfidentAI } from "confident-ai";
const client = new ConfidentAI();
const result = await client.rtFrameworks.deleteRiskCategory(
"<RT-FRAMEWORK-ID>",
"<RISK-CATEGORY-ID>",
);Parameters
| Parameter | Type | Description |
|---|---|---|
rtFrameworkId | string | Required. The id of the red teaming framework the category belongs to. |
riskCategoryId | string | Required. The id of the risk category. |
Returns
This method returns an object of type RiskCategoryRef.
Types
RiskCategory
One area of risk inside a framework, pairing the vulnerability types to probe for with the attack methods to probe with.
class RiskCategory:
id: str
name: str
description: Optional[str]
vulnerability_types: List[RiskCategoryVulnerabilityType] = Field(alias="vulnerabilityTypes")
attack_methods: List[RiskCategoryAttackMethod] = Field(alias="attackMethods")
vulnerability_id_to_priority_level: Dict[str, int] = Field(alias="vulnerabilityIdToPriorityLevel")idstrRequired
The id of the risk category, generated by Confident AI.
Example: "<RISK-CATEGORY-ID>"
namestrRequired
The name of the risk category, unique within the framework.
Example: "Data protection"
descriptionOptional[str]Required
What this risk category covers.
Example: "Risks around leaking data the model was given."
vulnerability_typesList[RiskCategoryVulnerabilityType]Required
The vulnerability types this category probes for.
attack_methodsList[RiskCategoryAttackMethod]Required
The attack methods this category probes with.
vulnerability_id_to_priority_levelDict[str, int]Required
How much of the assessment each vulnerability gets, keyed by vulnerability id, from 0 to 3. A vulnerability with no entry runs at the default weight.
Example: {"<VULNERABILITY-ID>":2}
interface RiskCategory {
id: string;
name: string;
description: string | null;
vulnerabilityTypes: RiskCategoryVulnerabilityType[];
attackMethods: RiskCategoryAttackMethod[];
vulnerabilityIdToPriorityLevel: Record<string, number>;
}idstringRequired
The id of the risk category, generated by Confident AI.
Example: "<RISK-CATEGORY-ID>"
namestringRequired
The name of the risk category, unique within the framework.
Example: "Data protection"
descriptionstring | nullRequired
What this risk category covers.
Example: "Risks around leaking data the model was given."
vulnerabilityTypesRiskCategoryVulnerabilityType[]Required
The vulnerability types this category probes for.
attackMethodsRiskCategoryAttackMethod[]Required
The attack methods this category probes with.
vulnerabilityIdToPriorityLevelRecord<string, number>Required
How much of the assessment each vulnerability gets, keyed by vulnerability id, from 0 to 3. A vulnerability with no entry runs at the default weight.
Example: {"<VULNERABILITY-ID>":2}
RiskCategoryAttackMethod
An attack method selected into a risk category.
class RiskCategoryAttackMethod:
id: str
name: str
multi_turn: bool = Field(alias="multiTurn")idstrRequired
The id of the attack method.
Example: "<ATTACK-METHOD-ID>"
namestrRequired
The name of the attack method.
Example: "Prompt Injection"
multi_turnboolRequired
Whether the attack plays out over a conversation rather than a single request.
Example: false
interface RiskCategoryAttackMethod {
id: string;
name: string;
multiTurn: boolean;
}idstringRequired
The id of the attack method.
Example: "<ATTACK-METHOD-ID>"
namestringRequired
The name of the attack method.
Example: "Prompt Injection"
multiTurnbooleanRequired
Whether the attack plays out over a conversation rather than a single request.
Example: false
RiskCategoryList
One page of risk categories, with the total across all pages.
class RiskCategoryList:
risk_categories: List[RiskCategorySummary] = Field(alias="riskCategories")
total_risk_categories: int = Field(alias="totalRiskCategories")
page: int
page_size: int = Field(alias="pageSize")risk_categoriesList[RiskCategorySummary]Required
The risk categories for the current page, ordered by name.
See RiskCategorySummary.
total_risk_categoriesintRequired
The total number of risk categories in this framework.
Example: 8
pageintRequired
The page this response covers.
Example: 1
page_sizeintRequired
The number of risk categories per page.
Example: 25
interface RiskCategoryList {
riskCategories: RiskCategorySummary[];
totalRiskCategories: number;
page: number;
pageSize: number;
}riskCategoriesRiskCategorySummary[]Required
The risk categories for the current page, ordered by name.
See RiskCategorySummary.
totalRiskCategoriesnumberRequired
The total number of risk categories in this framework.
Example: 8
pagenumberRequired
The page this response covers.
Example: 1
pageSizenumberRequired
The number of risk categories per page.
Example: 25
RiskCategoryRef
A reference to a risk category by its id.
class RiskCategoryRef:
id: stridstrRequired
The id of the risk category, generated by Confident AI.
Example: "<RISK-CATEGORY-ID>"
interface RiskCategoryRef {
id: string;
}idstringRequired
The id of the risk category, generated by Confident AI.
Example: "<RISK-CATEGORY-ID>"
RiskCategorySummary
A risk category as it appears in a list: what it covers and how much it selects, without naming the selections.
class RiskCategorySummary:
id: str
name: str
description: Optional[str]
num_vulnerability_types: int = Field(alias="numVulnerabilityTypes")
num_attack_methods: int = Field(alias="numAttackMethods")idstrRequired
The id of the risk category, generated by Confident AI.
Example: "<RISK-CATEGORY-ID>"
namestrRequired
The name of the risk category, unique within the framework.
Example: "Data protection"
descriptionOptional[str]Required
What this risk category covers.
Example: "Risks around leaking data the model was given."
num_vulnerability_typesintRequired
How many vulnerability types the category selects.
Example: 4
num_attack_methodsintRequired
How many attack methods the category selects.
Example: 3
interface RiskCategorySummary {
id: string;
name: string;
description: string | null;
numVulnerabilityTypes: number;
numAttackMethods: number;
}idstringRequired
The id of the risk category, generated by Confident AI.
Example: "<RISK-CATEGORY-ID>"
namestringRequired
The name of the risk category, unique within the framework.
Example: "Data protection"
descriptionstring | nullRequired
What this risk category covers.
Example: "Risks around leaking data the model was given."
numVulnerabilityTypesnumberRequired
How many vulnerability types the category selects.
Example: 4
numAttackMethodsnumberRequired
How many attack methods the category selects.
Example: 3
RiskCategoryVulnerabilityType
A vulnerability type selected into a risk category.
class RiskCategoryVulnerabilityType:
id: str
name: str
vulnerability_id: str = Field(alias="vulnerabilityId")
vulnerability_name: str = Field(alias="vulnerabilityName")idstrRequired
The id of the vulnerability type.
Example: "<VULNERABILITY-TYPE-ID>"
namestrRequired
The name of the vulnerability type.
Example: "System prompt disclosure"
vulnerability_idstrRequired
The id of the vulnerability this type belongs to.
Example: "<VULNERABILITY-ID>"
vulnerability_namestrRequired
The name of the vulnerability this type belongs to.
Example: "Prompt Leakage"
interface RiskCategoryVulnerabilityType {
id: string;
name: string;
vulnerabilityId: string;
vulnerabilityName: string;
}idstringRequired
The id of the vulnerability type.
Example: "<VULNERABILITY-TYPE-ID>"
namestringRequired
The name of the vulnerability type.
Example: "System prompt disclosure"
vulnerabilityIdstringRequired
The id of the vulnerability this type belongs to.
Example: "<VULNERABILITY-ID>"
vulnerabilityNamestringRequired
The name of the vulnerability this type belongs to.
Example: "Prompt Leakage"
Last updated on