Salad-Data LLM Safety Evaluation Benchmark
Source, license and coverage
Supplier documentation. These claims are separate from the automated sample score. A listing edit date is not a data freshness date.
- License
- apache-2.0
- Source / creator
- OpenSafetyLab/Salad-Data
- Collection method
- The authors aggregated harmful prompts from eight existing open-source safety benchmarks (15,885 prompts) and augmented them with 15,433 self-instructed prompts generated by a fine-tuned GPT-3.5 to broaden coverage across a hierarchical 3-level harm taxonomy (6 domains → 16 tasks → 66 categories). Prompts were deduplicated and categorized; the paper also introduces attack-enhanced and defense-enhanced variants generated by applying jailbreak templates to the base set.
- Coverage start
- Not documented
- Coverage end
- Not documented
- Data last updated
- Not documented
- Update schedule
- Not documented
Primarily English with a small multilingual subset (230 prompts); harm taxonomy reflects authors' choices and may not align with other safety frameworks. Self-instructed prompts inherit GPT-3.5 biases. Dataset is from early 2024 — newer jailbreak techniques (e.g., recent multi-turn or vision-based attacks) are not represented. Significant overlap with widely-used benchmarks (AdvBench, HH-RLHF) means leakage risk if used to train models that will be evaluated on those benchmarks.
Sample structure score: 100 / 100
This automated check describes the inspected sample, not factual accuracy, legal rights, representativeness, or the quality of the entire dataset. It is not a customer rating.
Assessed 10 sample records (JSON) on 2026-10-09. All records in the provided sample were checked.
| Check | Points | Evidence |
|---|---|---|
| Populated cells | 50 / 50 | 80 of 80 top-level cells contain a value. Null, absent and blank values count as missing; zero and false count as populated. |
| Consistent value types | 30 / 30 | 80 of 80 populated cells match their column's most common observed type. Types are inferred, not checked against real-world truth. |
| Consistent record shape | 20 / 20 | 10 of 10 records have the expected fields. CSV/TSV use the header width; JSON uses the union of observed keys. |
Field-level findings and improvements
Check missing cells and mixed types below. Document intentional missing values or mixed types in your field descriptions. Do not fill legitimate unknowns with invented values just to increase this score.
| Field | Missing cells | Most common type | Other populated types |
|---|---|---|---|
| 3-category | 0 / 10 | string | 0 / 10 |
| daugq | 0 / 10 | string | 0 / 10 |
| qid | 0 / 10 | number | 0 / 10 |
| dmethod | 0 / 10 | string | 0 / 10 |
| baseq | 0 / 10 | string | 0 / 10 |
| 2-category | 0 / 10 | string | 0 / 10 |
| 1-category | 0 / 10 | string | 0 / 10 |
| did | 0 / 10 | number | 0 / 10 |
About this data
Aggregated safety questions for LLM red-teaming and jailbreak evaluation, sourced from HH-RLHF, AdvBench, ToxicChat, GPTFuzzer, and GPT-3.5 self-instructed prompts.
Retrieve with your agent or Python
Create an account and configure DATABAZAAR_API_KEY. This example retrieves free or already purchased data; it never makes a purchase. For a multi-file dataset, choose a file index from the manifest.
Download the Python examplepython3 retrieve-dataset.py bae7e438-2cf7-4e24-9969-c5f10cac48e9 --output dataset.bin
Full supplier documentation
Schema
| Name | Type | Description |
|---|---|---|
| 3-category | VARCHAR | Fine-grained harm category label (e.g., O12: Religious Stereotyping, O42: Scams) |
| daugq | VARCHAR | Augmented/jailbreak variant of the base question with defensive prompt injection technique applied |
| qid | BIGINT | Unique question identifier linking base and augmented versions |
| dmethod | VARCHAR | Jailbreak/defense method name applied to generate the augmented prompt (e.g., reminder_prompt, xsafe_prompt) |
| baseq | VARCHAR | Original harmful or sensitive prompt without augmentation or jailbreak attempt |
| 2-category | VARCHAR | Mid-level harm category label (e.g., O2: Unfair Representation, O12: Fraud or Deceptive Action) |
| 1-category | VARCHAR | Top-level harm taxonomy label (e.g., O1: Representation & Toxicity, O5: Malicious Use) |
| did | BIGINT | Unique identifier for the augmented question/defense pair |
Sample Data
Preview a sample of the data before downloading.
Public sample only. Sign in to retrieve the full dataset, including free datasets.
For AI Agents
# 1. Add to your agent's MCP config (claude_desktop_config.json or similar):
{
"mcpServers": {
"databazaar": { "command": "npx", "args": ["databazaar-mcp"] }
}
}
# 2. Your agent can then call:
search_datasets({ query: "Salad-Data LLM Safety Evaluati" })
// Found: bae7e438-2cf7-4e24-9969-c5f10cac48e9
get_download_url({ dataset_id: "bae7e438-2cf7-4e24-9969-c5f10cac48e9" }) // free — sign in with MCP OAuth first# Free dataset — sign in or use your account API key: curl https://api.databazaar.io/datasets/bae7e438-2cf7-4e24-9969-c5f10cac48e9/download-url -H "Authorization: Bearer $DATABAZAAR_API_KEY"