> ## Documentation Index
> Fetch the complete documentation index at: https://evalgate.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Create red team risk packs

> Requires scopes: red_team:approve



## OpenAPI

````yaml /api-reference/openapi.json post /api/red-team/risk-packs
openapi: 3.1.0
info:
  title: EvalGate API
  version: 3.7.6
  description: EvalGate API. See docs/api-contract.md for stability commitments.
servers:
  - url: https://evalgate.com
    description: Production
  - url: http://localhost:3000
    description: Local
security: []
paths:
  /api/red-team/risk-packs:
    post:
      tags:
        - red team
      summary: Create red team risk packs
      description: 'Requires scopes: red_team:approve'
      operationId: post_red_team_risk_packs
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/PostApiRedTeamRiskPacksRequest'
      responses:
        '201':
          description: Successful response
          content:
            application/json:
              schema:
                $ref: >-
                  #/components/schemas/PostApiRedTeamRiskPacksResponse201ApplicationJson
        '400':
          $ref: '#/components/responses/ValidationError'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        '409':
          $ref: '#/components/responses/Conflict'
        '429':
          $ref: '#/components/responses/RateLimited'
        '500':
          $ref: '#/components/responses/InternalError'
      security:
        - bearerAuth:
            - red_team:approve
components:
  schemas:
    PostApiRedTeamRiskPacksRequest:
      type: object
      properties:
        packKey:
          type: string
        taxonomy:
          type: string
        taxonomyVersion:
          type: string
        cases:
          type: array
          items:
            type: object
            properties:
              input:
                type: string
              severity:
                oneOf:
                  - type: string
                    enum:
                      - low
                  - type: string
                    enum:
                      - medium
                  - type: string
                    enum:
                      - high
                  - type: string
                    enum:
                      - critical
              category:
                oneOf:
                  - type: string
                    enum:
                      - prompt_injection
                  - type: string
                    enum:
                      - data_exfiltration_privacy
                  - type: string
                    enum:
                      - harmful_content
                  - type: string
                    enum:
                      - misinformation_hallucination
                  - type: string
                    enum:
                      - authorization_bypass
                  - type: string
                    enum:
                      - tool_misuse
                  - type: string
                    enum:
                      - excessive_agency
                  - type: string
                    enum:
                      - insecure_output_handling
                  - type: string
                    enum:
                      - sensitive_data_disclosure
                  - type: string
                    enum:
                      - policy_evasion
                  - type: string
                    enum:
                      - denial_of_wallet
                  - type: string
                    enum:
                      - jailbreak_robustness
              caseKey:
                type: string
              technique:
                type: string
              expectedSafeBehavior:
                type: string
              source:
                oneOf:
                  - type: string
                    enum:
                      - imported
                  - type: string
                    enum:
                      - built_in
              successIndicators:
                type: array
                items:
                  type: string
            additionalProperties: false
            required:
              - input
              - severity
              - category
              - caseKey
              - technique
              - expectedSafeBehavior
        displayName:
          type: string
      additionalProperties: false
      required:
        - packKey
        - taxonomy
        - taxonomyVersion
        - cases
    PostApiRedTeamRiskPacksResponse201ApplicationJson:
      type: object
      properties:
        pack:
          type: object
          properties:
            status:
              type: string
            id:
              type: string
            createdAt:
              type: string
              format: date-time
            organizationId:
              $ref: '#/components/schemas/OrganizationId'
            createdBy:
              type: string
            version:
              type: number
            artifactId:
              type: number
            contentHash:
              type: string
            reviewRationale:
              oneOf:
                - type: 'null'
                - type: string
            reviewedBy:
              oneOf:
                - type: 'null'
                - type: string
            reviewedAt:
              oneOf:
                - type: 'null'
                - type: string
                  format: date-time
            artifactVersionId:
              type: number
            packKey:
              type: string
            taxonomy:
              type: string
            taxonomyVersion:
              type: string
            packSnapshot:
              type: object
              additionalProperties:
                $ref: '#/components/schemas/JsonValue'
          additionalProperties: false
          required:
            - status
            - id
            - createdAt
            - organizationId
            - createdBy
            - version
            - artifactId
            - contentHash
            - reviewRationale
            - reviewedBy
            - reviewedAt
            - artifactVersionId
            - packKey
            - taxonomy
            - taxonomyVersion
            - packSnapshot
        cases:
          type: array
          items:
            type: object
            properties:
              input:
                type: string
              severity:
                oneOf:
                  - type: string
                    enum:
                      - low
                  - type: string
                    enum:
                      - medium
                  - type: string
                    enum:
                      - high
                  - type: string
                    enum:
                      - critical
              id:
                type: string
              createdAt:
                type: string
                format: date-time
              organizationId:
                $ref: '#/components/schemas/OrganizationId'
              createdBy:
                type: string
              contentHash:
                type: string
              source:
                type: string
              category:
                oneOf:
                  - type: string
                    enum:
                      - prompt_injection
                  - type: string
                    enum:
                      - data_exfiltration_privacy
                  - type: string
                    enum:
                      - harmful_content
                  - type: string
                    enum:
                      - misinformation_hallucination
                  - type: string
                    enum:
                      - authorization_bypass
                  - type: string
                    enum:
                      - tool_misuse
                  - type: string
                    enum:
                      - excessive_agency
                  - type: string
                    enum:
                      - insecure_output_handling
                  - type: string
                    enum:
                      - sensitive_data_disclosure
                  - type: string
                    enum:
                      - policy_evasion
                  - type: string
                    enum:
                      - denial_of_wallet
                  - type: string
                    enum:
                      - jailbreak_robustness
              reviewRationale:
                oneOf:
                  - type: 'null'
                  - type: string
              reviewedBy:
                oneOf:
                  - type: 'null'
                  - type: string
              reviewedAt:
                oneOf:
                  - type: 'null'
                  - type: string
                    format: date-time
              reviewStatus:
                type: string
              riskPackVersionId:
                type: string
              caseKey:
                type: string
              technique:
                type: string
              expectedSafeBehavior:
                type: string
              successIndicators:
                type: array
                items:
                  type: string
              generatedModelCallId:
                oneOf:
                  - type: 'null'
                  - type: string
            additionalProperties: false
            required:
              - input
              - severity
              - id
              - createdAt
              - organizationId
              - createdBy
              - contentHash
              - source
              - category
              - reviewRationale
              - reviewedBy
              - reviewedAt
              - reviewStatus
              - riskPackVersionId
              - caseKey
              - technique
              - expectedSafeBehavior
              - successIndicators
              - generatedModelCallId
        release:
          type: object
          properties:
            status:
              oneOf:
                - type: string
                  enum:
                    - draft
                - type: string
                  enum:
                    - canary
                - type: string
                  enum:
                    - paused
                - type: string
                  enum:
                    - live
                - type: string
                  enum:
                    - selected
                - type: string
                  enum:
                    - candidate
                - type: string
                  enum:
                    - rolled_back
            rationale:
              oneOf:
                - type: 'null'
                - type: string
            summary:
              type: object
              additionalProperties:
                $ref: '#/components/schemas/JsonValue'
            createdAt:
              type: string
            updatedAt:
              type: string
            createdBy:
              type: string
            metadata:
              oneOf:
                - type: 'null'
                - type: object
                  additionalProperties:
                    $ref: '#/components/schemas/JsonValue'
            environment:
              oneOf:
                - type: 'null'
                - type: string
                  enum:
                    - dev
                - type: string
                  enum:
                    - staging
                - type: string
                  enum:
                    - prod
            kind:
              oneOf:
                - type: string
                  enum:
                    - prompt
                - type: string
                  enum:
                    - judge_config
                - type: string
                  enum:
                    - policy_pack
                - type: string
                  enum:
                    - ruleset
            artifactId:
              type: number
            versionId:
              type: number
            payload:
              type: object
              additionalProperties:
                $ref: '#/components/schemas/JsonValue'
            versionNumber:
              type: number
            displayName:
              oneOf:
                - type: 'null'
                - type: string
            promotedBy:
              oneOf:
                - type: 'null'
                - type: string
            key:
              type: string
          additionalProperties: false
          required:
            - status
            - rationale
            - summary
            - createdAt
            - updatedAt
            - createdBy
            - metadata
            - environment
            - kind
            - artifactId
            - versionId
            - payload
            - versionNumber
            - displayName
            - promotedBy
            - key
      additionalProperties: false
      required:
        - pack
        - cases
        - release
    OrganizationId:
      type: string
      format: uuid
    JsonValue:
      oneOf:
        - type: 'null'
        - type: boolean
        - type: number
        - type: string
        - type: array
          items:
            $ref: '#/components/schemas/JsonValue'
        - type: object
          additionalProperties:
            $ref: '#/components/schemas/JsonValue'
    ApiError:
      type: object
      properties:
        error:
          type: object
          properties:
            code:
              type: string
              enum:
                - UNAUTHORIZED
                - FORBIDDEN
                - NOT_FOUND
                - VALIDATION_ERROR
                - RATE_LIMITED
                - CONFLICT
                - INTERNAL_ERROR
                - SERVICE_UNAVAILABLE
                - QUOTA_EXCEEDED
                - NO_ORG_MEMBERSHIP
                - CROSS_ORG_REFERENCE
                - INCOMPLETE
                - MALFORMED
            message:
              type: string
            details: {}
            requestId:
              type: string
              format: uuid
          required:
            - code
            - message
      required:
        - error
  responses:
    ValidationError:
      description: Validation error
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ApiError'
    Unauthorized:
      description: Unauthorized
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ApiError'
    Forbidden:
      description: Forbidden
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ApiError'
    NotFound:
      description: Resource not found
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ApiError'
    Conflict:
      description: Conflict
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ApiError'
    RateLimited:
      description: Rate limit exceeded
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ApiError'
    InternalError:
      description: Internal server error
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ApiError'
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: API Key or Session Token

````