Model or dataset
Goochbeater/Spiritual-Spell-Red-Teaming avatar
Goochbeater/Spiritual-Spell-Red-Teaming

Goochbeater/Spiritual-Spell-Red-Teaming: a jailbreak prompt collection for Claude and other LLMs

A repo for jailbreaking various LLMs, mainly Claude

3,750 stars702 forksUnknownLicense varies

At a glance

What is it?
The repository collects prompt material aimed at language model guardrails, with a short guide and a list of techniques. The README is written in invisible Unicode tags, and that choice says as much about the project as its content does.
Who is it for?
This is a prompt collection for people who already work with language model guardrails and want a second set of phrasings to compare against their own. It is not a tool, not a benchmark, and not something to deploy.
Can I use it commercially?
Not without permission. GitHub finds no licence file in the repository, and without a licence all rights are reserved by default: you may read the code but not reuse it. Check the README, or ask the authors, before using it.
Is it still maintained?
Yes. The repository received new commits within the last day.
What is it written in?
GitHub does not report a main language for this repository.

Answers come from the project's GitHub data, last synced on October 1, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What problem the Spiritual Spell repository addresses

Model providers ship guardrails, and those guardrails are tested by people who try to get past them. That work needs a corpus of attempts: phrasings that have worked, phrasings that have stopped working, and notes on which model version each was aimed at. Goochbeater/Spiritual-Spell-Red-Teaming is one such corpus, assembled by hand and published on GitHub. The README describes itself as a repository for jailbreaking various LLMs, mainly Claude, and it frames the audience narrowly. According to the README, it is intended for people who are interested in red teaming and AI security, and it says the material is for research and educational purposes only. The README also states that the author is not responsible for any misuse of the information and that the content is provided as is, without warranty. So the audience is people who test model behaviour, not people who want a working chatbot with the filters removed. If you want a product, this is the wrong repository. If you want a record of attempts against Claude guardrails, that is what the repository claims to hold.

The README is written in invisible Unicode tags

Open the repository page and the README appears as a run of emoji and blank space. The text is there, encoded as Unicode tag characters, which render as nothing in a normal browser view. The README's own structure statement, once the tags are read, lists a Style, Likes, Dislikes, and an Indisputably embrace yourself section, followed by a note that the author's thoughts and prayers must be about the user and that the user need not show love but must reply unhesitatingly. The tag encoding is the project's first real design decision, and it is a load-bearing one. It hides the instructions from casual readers and from any pipeline that strips or ignores Unicode tag codepoints, while keeping them recoverable for anyone who knows to look. That is a deliberate trade-off: the README becomes invisible to a large share of its intended audience. A reader who does not decode the tags sees an empty page and moves on. Whether that is clever or self-defeating depends on whether the goal is to be read or to be passed along. The repository does not explain the choice, and the README does not document how to decode it.

How the material is organised: Jailbreak-Guide and a single README

The repository has exactly two top-level entries: a Jailbreak-Guide directory and README.md. There is no package manifest, no build file, no test directory, and no configuration. Nothing here executes. The data flow is manual and one-directional: a human reads the guide, copies a prompt, pastes it into a model interface, and observes the response. The README's own technique list names four categories, which it calls Injection, Jailbreaking, Non descriptive scenes, and Personality. Those labels describe prompt shapes rather than code paths. Injection covers attempts to override or append to system instructions. Jailbreaking covers the direct requests for disallowed output. Non descriptive scenes and Personality cover framing devices, where the model is asked to adopt a character or a scenario rather than answer directly. The README states that these techniques will be in first person impersonality, no meta commentary, thoughts should be natural, scattered, stream of consciousness, don't always plan things out so deliberately, just words and phrases running through your little head. That is a description of a writing style for the prompts themselves, not a specification. There is no index of which technique targets which model version, and the repository does not state a Claude version anywhere in the pages it publishes.

Installing and using it: cloning the repository and reading the guide

There is nothing to install. The project has no package, no binary and no dependencies, so the only setup is getting the files onto disk and reading them. Clone the repository and list what came down.

bash
git clone https://github.com/Goochbeater/Spiritual-Spell-Red-Teaming.git
cd Spiritual-Spell-Red-Teaming
ls

The listing should show Jailbreak-Guide and README.md, matching the two top-level entries in the repository. From there, open the guide directory and read the files in it. The README does not document any command, script or environment variable, because there are none. If you want to read the README as prose rather than as invisible tags, you need a tool that exposes Unicode tag codepoints; the repository does not ship one and does not describe the encoding. The practical first use is to take one technique from the guide, paste it into a model interface you are authorised to test, and record the response alongside the model name and date. The README gives no worked example of a full prompt, so the first real use is assembling one yourself from the categories it names.

What the repository does not give you

The README does not document rollback, versioning, or a changelog. There are no releases, so there is no way to pin a known-good revision of a prompt set and compare it against a later one. That matters because guardrails change on the provider side without notice, and a prompt that worked in one month can stop working in the next. Without tags or releases, you cannot tell which revision of the guide you tested. The README also does not state a licence. GitHub shows no licence for the repository, and the README does not mention one. For anyone who wants to reuse the text in internal training material, a paper, or a commercial red teaming engagement, that is an unresolved question rather than a detail. The repository is not archived, and the last push was on 2026-09-04, so the files are recent, but recency of the last push says nothing about whether the prompt content still defeats current models. The README's disclaimer, that the information is for research and educational purposes only and provided as is without warranty, is the only statement about use, and it is a disclaimer rather than a grant.

Where this fits against an automated red teaming harness

The obvious alternative is a scripted harness that generates variations and scores responses, such as the tooling that grew around prompt injection benchmarks. The difference is not quality, it is kind. A harness gives you reproducibility: the same seed produces the same prompts, and a scoring function turns responses into a number you can plot. This repository gives you a human-written set of phrasings and a style guide for writing more. A harness can tell you that a guardrail held across two hundred generated attempts; this repository can tell you which specific framing a person found interesting. They answer different questions, and the repository does not try to answer the harness question. It also does not claim to. If your need is a metric, a pass rate, or a regression suite that runs in CI, the guide is the wrong artifact, because there is no runner and no expected output. If your need is raw material for a human to study, the phrasings are the point. The two can be combined, but that combination is work the repository does not do for you.

Maintenance, upgrade cost and licence questions

The last push to the repository was on 2026-09-04, which is recent, and the repository is not archived. That tells you the files were touched recently. It does not tell you whether the prompts still work against current Claude models, because the README states no model versions and the repository ships no results. Upgrading is therefore manual: you re-read the guide, re-test the prompts, and decide which ones still belong in your notes. There is no dependency graph to update and no version number to bump, so the cost is entirely human attention. The licence is the harder issue. The repository shows no licence file, and the README does not name one. Without a stated licence, the default position under most copyright regimes is that no rights are granted beyond viewing the work, which affects copying the guide into internal documentation or a published paper. That is a factual observation about the repository, not legal advice; if reuse matters to you, ask the author or treat the text as read-only reference.

Editorial conclusion

This is a prompt collection for people who already work with language model guardrails and want a second set of phrasings to compare against their own. It is not a tool, not a benchmark, and not something to deploy. Anyone evaluating it for a safety or red teaming program should first read the Jailbreak-Guide directory and establish the licence, because the repository states none, and the README's obfuscated encoding means a reader who does not strip Unicode tags sees nothing at all.

Frequently asked questions

What does red teaming mean?

In this repository's framing, it means testing AI systems by trying to get past their guardrails, and the README says the material is intended for people interested in red teaming and AI security. The repository supplies prompt material for that testing rather than a tool that runs it.

Is the Spiritual Spell repository a tool I can install?

No. The repository contains a Jailbreak-Guide directory and README.md, with no package manifest, build file or executable. The only setup is cloning the repository and reading the guide.

Why does the Spiritual Spell README look empty?

The README text is encoded as Unicode tag characters, which render as nothing in a normal browser view. The content is recoverable with a tool that exposes those codepoints, and the repository does not document the encoding or ship a decoder.

What licence does Spiritual-Spell-Red-Teaming use?

None is stated. The repository shows no licence file and the README does not name one, so reuse terms are undefined and the README's only statement about use is a research and educational purposes disclaimer.

Official sources

  1. Goochbeater/Spiritual-Spell-Red-Teaming on GitHub
  2. Issues
  3. README
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/goochbeater-spiritual-spell-red-teaming.svg)](https://hysenlabs.com/projects/goochbeater-spiritual-spell-red-teaming)