Favicon of DeepTeam

DeepTeam

An open-source Python framework for testing LLMs and AI agents locally, with adversarial attacks, production guardrails, and Apache 2.0 licensing.

Screenshot of DeepTeam website

DeepTeam is a Python framework that runs locally to test chatbots, AI agents, and retrieval-augmented generation (RAG) pipelines for security and safety failures. Built on DeepEval, it's open source under Apache 2.0 and aimed at developers and security teams assessing AI applications before deployment or during ongoing development.

It uses LLMs to generate adversarial attacks and judge the responses, returning pass/fail results with explanations. Tests cover prompt injection, jailbreaks, personal data leakage, bias, and SQL injection. Agent-specific checks examine excessive authority, abuse of tool calls, and attacks on communication between agents. Multi-turn attacks include Crescendo and Bad-Likert-Judge, which probe failures across a conversation rather than a single prompt.

Risk assessments can follow OWASP Top 10 for LLMs, MITRE ATLAS, NIST AI RMF, and EU AI Act controls. BeaverTails and Aegis provide safety test datasets. Production guardrails check for prompt injection, privacy leaks, harmful content, hallucinations, and cybersecurity risks.

The framework runs on your machine, but it can use cloud model providers such as OpenAI, Claude, Gemini, Azure OpenAI, and AWS Bedrock. Local execution doesn't make those provider calls local. Integrations with GitHub Actions and GitLab CI let teams repeat security tests as their applications change.

Confident AI is a separate hosted platform for tracking assessments, monitoring production vulnerabilities, and sharing reports. Its MCP server connects these tasks to Cursor and Claude Code.

Similar to DeepTeam