Prove it. Prevail.
Red-team open Vision-Language-Action (VLA) robot policies in simulation, and get an attack-success rate beside the control it is read against.
A VLA policy turns a camera image and an instruction into motor commands. It can be pushed off course the way a language model is jailbroken, except the failure moves an arm. Provael is the open-source tool that measures that, honestly: an attack-success rate with its 95 % interval, a benign control, a competence control, and an evidence label that says whether a real policy or the CPU fixture produced it — then the artifacts a review needs (SARIF, OSCAL, a CycloneDX ML-BOM, a test report, a signed attestation).
What it is not. Simulation only — no physical robot, no real-world-harm payload. Evidence, not certification. A measurement of this checkpoint under this protocol, never a safety proof.
➡️ provael — the CLI. CPU-first, Apache-2.0, one
command to a deterministic run; a GPU and the [lerobot] extra for a real policy.
➡️ The measured result — one real policy, ten tasks, every rate with its control and interval, the nulls published beside the finding, and the corrections register that goes with them. Read it there rather than here: this page holds no numbers, because a number typed into an unguarded page is how a stale claim survives.
➡️ Documentation · The Embodied AI Security Top 10 (an independent community list, CC-BY-SA 4.0 — not a Provael product, not affiliated with the OWASP® Foundation or MITRE®).
One maintainer, Sattyam Jain, in the open — wins and dead ends both. Reproductions of the published result, whichever way they come out, are the contribution the project is short of: the reproduction request has everything needed to attempt one.
🔗 provael.com · ✉️ hello@provael.com · 🐦 @getprovael