From install to a measured attack, in five minutes.
Provael is CPU-first and Apache-2.0. Install it, run the full attack suite against the deterministic stub with no GPU, and read a scorecard you can file. Here is the whole path.
Install
One package, pure Python. The CPU-first core and every attack family install with it.
Or with no local Python at all — multi-arch, public, works logged out:
Run your first attack
Sweep the four core attack families (EAI01/02/04/05) against the deterministic CPU stub. Runs anywhere, no GPU, in seconds — then widen it with --attacks.
Real-model transfer (the SmolVLA result) needs the optional [lerobot] extra and a GPU:
Read the scorecard
Every run emits an attack-success rate with a 95% Wilson CI, a benign control, and a SARIF report that drops into GitHub code scanning. Gate your build on it.

The reworded-instruction attack, end to end: install, run, scorecard. Recorded July 2026 on a single task; the scorecard in it reads 100%. The current result is 44/50 across all ten tasks.
You installed it. Now see what it measures.
The five-minute path ends with a number. These are the pages that show what the number means and where it fits.
The measured result
One reworded instruction drove a real SmolVLA policy off its benign task on 44 of 50 trials. The number, the nulls, and what it does not mean.
The Embodied AI Security Top 10
The risk list a robot policy actually faces, each with a definition, a real example, and how Provael tests it.
Crosswalk to the clocks
How a red-team result maps to the EU AI Act, Machinery Regulation, ISO 10218 and more. Evidence, not certification.
Score your fleet
Two minutes, six questions. An honest gap snapshot against the Top 10 and the compliance deadlines that are arriving.