$npx skillfedfor your agent

deepteam

The LLM Red Teaming Framework

Worth itPyPI TestingReleased Aug 202682.1K downloads / moApache-2.0Pure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — deepteam-1.0.9-py3-none-any.whl
v1.0.9 · released 2026-08-12 · Python <3.14,>=3.9 · 8 runtime deps: aiohttp, deepeval, grpcio, openai, pyyaml, requests, tabulate, tqdm

Yes. DeepTeam is actively maintained, has no known vulnerabilities, runs with low install friction, and addresses a critical gap in LLM security testing. It is permissively licensed and supports current Python versions. Install it if you are building or deploying LLM systems and need systematic vulnerability assessment before production.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires an LLM API key (e.g., OpenAI) to run attacks; local evaluation uses an LLM-as-a-Judge pattern, so you need access to a model for both attack generation and scoring.
  • Low install friction with a pure-Python wheel distribution.
  • Active maintenance with a recent release (2 days old) and 2445 repository stars.

License · maintenance · safety

Apache-2.0 (permissive) — Apache-2.0 permissive license allows commercial and private use with minimal restrictions, requiring only attribution and disclosure of modifications.

last release 2026-08-12 (2 days) · last repo commit 2026-08-12 · 2,445 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 82,123 downloads/mo, #14,181 on PyPI

Verify before relying

pip install deepteam

from deepteam import RedTeamer
from openai import OpenAI

client = OpenAI()
red_teamer = RedTeamer(client=client)
results = red_teamer.run_vulnerability_scan()
  • Whether the 50+ vulnerabilities and 20+ attack methods are all functional in version 1.0.9 or if some are still in development.
  • Performance characteristics and typical runtime for scanning a single LLM endpoint or agent.
  • Whether guardrails can be deployed as middleware or require code changes to the target LLM system.
Same gist for agents: .md · .json

What it is and what it does

DeepTeam is a red teaming framework built on top of DeepEval that lets you test LLM systems for security and safety vulnerabilities by simulating attacks locally on your machine. It covers a broad attack surface: data privacy (PII leakage, prompt leakage), responsible AI (bias, toxicity, fairness), security (SQL injection, SSRF, authorization bypasses), safety (illegal activity, self-harm), business risks (misinformation, IP violations), and agentic-specific threats (goal theft, recursive hijacking, tool abuse). Each vulnerability is tested using LLM-as-a-Judge metrics that produce binary pass/fail scores with reasoning.

The framework runs on Python 3.9–3.13 and depends on common packages like aiohttp, openai, grpcio, and requests. It offers both pre-built vulnerability checks and the ability to define custom vulnerabilities in code. Results can be managed through the optional Confident AI platform for risk tracking and team reporting, though the core framework runs entirely offline.

Use it for

  • Test a chatbot or AI agent for prompt injection and jailbreak vulnerabilities before deployment.
  • Audit a RAG pipeline for PII leakage and prompt leakage in retrieved context.
  • Verify that an LLM-powered system refuses illegal activity, self-harm requests, and harmful content.
  • Check multi-turn agent workflows for goal theft, recursive hijacking, and tool orchestration abuse.
  • Validate that an AI system exhibits fair treatment across demographic groups and does not exhibit bias.
  • Scan for authorization bypasses (BOLA, BFLA, RBAC) in LLM-powered APIs and tool-calling agents.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

Worth it

Yes.

DeepTeam is actively maintained, has no known vulnerabilities, runs with low install friction, and addresses a critical gap in LLM security testing. It is permissively licensed and supports current Python versions. Install it if you are building or deploying LLM systems and need systematic vulnerability assessment before production.

Install

deepteam on PyPI

Before you install

Low install friction with a pure-Python wheel distribution. Active maintenance with a recent release (2 days old) and 2445 repository stars. Depends on 8 runtime packages including aiohttp, openai, and grpcio, all of which are widely used.

Requires an LLM API key (e.g., OpenAI) to run attacks; local evaluation uses an LLM-as-a-Judge pattern, so you need access to a model for both attack generation and scoring.

License in practice

Apache-2.0 permissive license allows commercial and private use with minimal restrictions, requiring only attribution and disclosure of modifications.

Quickstart

pip install deepteam

from deepteam import RedTeamer
from openai import OpenAI

client = OpenAI()
red_teamer = RedTeamer(client=client)
results = red_teamer.run_vulnerability_scan()

Verify before relying

  • Whether the 50+ vulnerabilities and 20+ attack methods are all functional in version 1.0.9 or if some are still in development.
  • Performance characteristics and typical runtime for scanning a single LLM endpoint or agent.
  • Whether guardrails can be deployed as middleware or require code changes to the target LLM system.

Package facts

LicenseApache-2.0 permissive
Python supportSupports the current Python release <3.14,>=3.9
Install frictionLow. Pure-Python wheel
Runtime dependencies
8 packages
aiohttpdeepevalgrpcioopenaipyyamlrequeststabulatetqdm
MaintenanceActively maintained 2 days since the last release
Last repo commit
First released
Downloads82,123 / month, #14,181 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
License :: OSI Approved :: Apache Software LicenseProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.9

Evidence: deepteam-1.0.9-py3-none-any.whl

Tags

Capabilities
llm red teaming frameworkai security testingprompt injection detectionllm vulnerability assessmentadversarial attack simulationai agent penetration testingbias and safety testing for llms
Topics
llm-securityred-teamingai-safety

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “llm red teaming framework”

  • deepteamDeepTeam is an open-source red teaming framework that simulates…
  • dreadnodeDreadnode is an SDK for building, testing, and evaluating AI security…
  • pyritPyRIT is a framework for security professionals to identify and…

Give your agent the search over MCP, or paste the wish link into any chat.

More Testing packages

pluggy Worth it
PyPI · Libraries · released May 2025

Pluggy provides a plugin system that lets you define hook specifications and register implementations to be called in sequence, enabling extensible Python applications without tight coupling.

Install it if you're building an extensible application or framework.

MITpure Python · 3.9+aging
1.3Bdownloads / mo
pytest Worth it
PyPI · Libraries · released Jun 2026

pytest is a testing framework that lets you write test functions using plain assert statements and automatically discovers and runs them, with detailed failure reporting.

MITpure Python · 3.10+
1.1Bdownloads / mo
virtualenv Worth it
PyPI · Libraries · released Aug 2026

virtualenv creates isolated Python environments where packages can be installed independently without affecting the system Python or other projects.

MITpure Python · 3.9+
532.9Mdownloads / mo
coverage Worth it
PyPI · Testing · released Aug 2026

Coverage.py measures which lines of Python code are executed during test runs, reporting coverage percentages and identifying untested code paths.

Install it if you want to measure test completeness or enforce coverage thresholds in your project.

permissive licensepure Python · 3.10+
335.8Mdownloads / mo
pytest-asyncio Worth it
PyPI · Testing · released May 2026

pytest-asyncio is a pytest plugin that enables writing and running async test functions using the asyncio library, allowing developers to await code directly within test cases.

Install it if you write tests for any asyncio-based code.

Apache-2.0pure Python · 3.10+
275.9Mdownloads / mo
pytest-json-ctrf Worth it
PyPI · Testing · released Jul 2026

A pytest plugin that generates test reports in Common Test Report Format (CTRF) as JSON, compatible with pytest-xdist and pytest-playwright for distributed and browser-based testing.

Install it if you need CTRF-formatted test output for CI/CD integration or cross-tool reporting.

MITpure Python · 3.8+
273.0Mdownloads / mo

See also bingo-ai · dreadnode · pyrit · llm-guard · deepeval · garak · agentscope · hol-guard · atdd · datarobot-genai

Further reading