How to red-team a plan with multiple LLMs (step-by-step guide)

Red-teaming — attacking your own plan before reality does — is standard practice in security and increasingly in product and strategy work. The bottleneck was always people: assembling attackers with different specialties takes a workshop.

With multiple LLMs it takes minutes. This guide shows how Stress Test mode works in LLM Debate Council and how to get findings that are actually actionable, not generic.

How Stress Test mode is structured

One agent is assigned as the Defender of your plan; every other agent is an Attacker with a fixed angle: security, scalability, cost, UX, or legal. Attackers must produce concrete failure scenarios — when and why it breaks — not vague concerns.

From round two, attackers must target the defender's latest rebuttal specifically ('you said X — that's weak because Y'), so the attack deepens instead of repeating. The final synthesis is a structured vulnerability list: each finding with the defender's mitigation and a risk score.

Step by step

  • 1. Write the plan as a short brief: what you're doing, for whom, with what constraints. Paste it as the debate idea.
  • 2. Pick 4–6 agents from at least two different vendors — attacker diversity is the whole point.
  • 3. Choose Stress Test mode. The first agent becomes the Defender, so put your strongest model there.
  • 4. Turn on fact-check if the plan leans on numbers or regulations (claims get verified with sources).
  • 5. Run it. Watch the rounds live; if the attackers miss an angle you fear, inject it mid-debate with the expert-intervention field.
  • 6. Read the verdict as a work list: each vulnerability, its mitigation, its risk score. Export to PDF/DOCX (Pro) for the team.

Getting sharper attacks

Attack quality follows brief quality. Include real constraints (budget, deadline, team size, stack) — attackers use them to build credible failure scenarios. Name what you already know is weak: attackers verify whether your fix survives contact.

Give agents personas in their instructions for domain-specific bite: 'you are a GDPR lawyer', 'you are an SRE who has seen this architecture fail'. Personas steer each attacker's angle beyond the built-in five.

What multi-vendor adds over one model attacking itself

A single model asked to attack its own plan tends to raise polite, generic risks. Models from rival vendors — trained on different data with different alignment — genuinely find different holes. In practice the union of GPT + Claude + Grok attacks covers noticeably more surface, and the defender can't satisfy them all with one hand-wavy answer.

FAQ

How many attackers should I use?

Four to six agents total works best: one defender plus 3–5 attackers, ideally spanning two or more vendors. Beyond that the rounds get long without adding many new findings.

Can I add my own attack angle?

Yes — two ways: give an agent a persona in its instructions ('attack as a tax auditor'), or inject a directive mid-debate with the expert-intervention field, which every agent must address next round.

What plan tier do I need?

Stress Test is a Pro feature ($20/mo). Every plan includes built-in models and monthly credits, so a full session usually spends only a small share of your monthly credits; optionally you can plug in your own API keys and pay the provider directly (0 credits). PDF/DOCX export is also Pro.

Attack your plan before reality does

Free tier · bring your own API keys · 15 languages

How to red-team a plan with multiple LLMs (step-by-step guide) · LLM Debate Council