Skip to content
@promptfoo

promptfoo

Test your LLM apps
Promptfoo - AI security testing platform with detective red panda logo

Ship agents, not vulnerabilities

WebsiteDocsBlogDiscord

GitHub stars npm downloads License: MIT

AI security testing for LLMs, agents, and RAG systems

Trusted by 25% of the Fortune 500 and 350K+ developers


Important

Promptfoo is now part of OpenAI. Promptfoo remains open source under MIT, community contributions remain welcome, and we will continue supporting multiple providers and models. Read the announcement →


🚀 Quick Start

npx promptfoo@latest init
npx promptfoo@latest eval
npx promptfoo@latest view

Get Started → · Enterprise →


🛠️ What We Do

安全 Testing

  • Red Teaming — Automated vulnerability discovery with 100+ attack plugins
  • Code Scanning — Detect LLM security risks in your IDE and CI/CD

Evaluations


🔒 安全 & Privacy

What we detect:

  • Prompt injections and jailbreaks
  • PII and sensitive data leaks
  • Hallucinations and policy violations
  • Tool misuse and adversarial attacks

Compliance: SOC 2 Type II · ISO 27001 · HIPAA

Data model:

  • Evals — 100% local, API keys never leave your machine
  • Red teaming — Your target runs locally; attack generation via our API or bring your own keys

📦 项目

仓库 Description
promptfoo Test prompts, agents, and RAGs. Red teaming and vulnerability scanning for LLMs.
promptfoo-action GitHub Action for CI/CD security testing
evil-mcp-server Red team testing for Model Context Protocol servers
modelaudit Static scanner that detects malicious code, backdoors, and vulnerabilities in ML model files
promptfoo-python Python wrapper for promptfoo
js-rouge JavaScript ROUGE metrics for summarization evaluation

👥 Community

Connect: Discord · X/Twitter · Bluesky · LinkedIn

Contribute: Contributing Guide · Good First 问题 · Report 问题

Learn: LLM Vulnerability Database · 安全 Research Blog

Popular repositories Loading

  1. promptfoo promptfoo Public

    Test your prompts, agents, and RAGs. Red teaming/pentesting/vulnerability scanning for AI. 比较 performance of GPT, Claude, Gemini, DeepSeek, and more. Simple declarative configs with command li…

    TypeScript 24.7k 2.2k

  2. promptfoo-action promptfoo-action Public

    The GitHub Action for Promptfoo. Test your prompts, agents, and RAGs. AI Red teaming, pentesting, and vulnerability scanning for LLMs. 比较 performance of GPT, Claude, Gemini, Llama, and more. S…

    TypeScript 70 33

  3. modelaudit modelaudit Public

    安全 scanner for AI/ML model files. Detects malicious code, backdoors, and vulnerabilities before deployment

    Python 68 17

  4. evil-mcp-server evil-mcp-server Public

    An evil MCP server used for redteam testing

    TypeScript 31 13

  5. crabcode crabcode Public

    Generic tmux-based workspace manager for multi-repo development. Lightning-fast dev productivity tool.

    Shell 18 4

  6. mini-foo mini-foo Public archive

    Mini promptfoo used for interviews

    TypeScript 6 6

仓库

Showing 10 of 20 repositories

Top languages

Loading…

Most used topics

Loading…