DeepTeam: an open source red teaming framework for LLM systems
DeepTeam is a framework to red team LLMs and AI agents.
At a glance
- What is it?
- DeepTeam wraps 50+ vulnerability checks, adversarial attacks and guardrails into a Python package that runs on your own machine. It fits teams that already write pytest-style LLM tests and want the adversarial half in the same workflow.
- Who is it for?
- Adopt DeepTeam if your team already runs DeepEval-style tests in Python and wants vulnerability checks such as PII Leakage, Bias or SQL Injection wired into that workflow, with a judge model you choose. Do not adopt it if you need a hosted scanner, a signed pentest report, or a tool that works without an LLM judge.
- Can I use it commercially?
- Yes. Apache-2.0 is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
- Is it still maintained?
- Yes. The repository last received commits 9 days ago.
- What is it written in?
- Mainly Python, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 22, 2026, and from our analysis. They are not legal advice.
Editorial analysis
What DeepTeam actually red teams, and who it is for
DeepTeam describes itself as "a simple-to-use, open-source red teaming framework for LLM systems" and frames the work as "penetration testing, but for LLMs". The target is not a network or a binary. It is an AI agent, a RAG pipeline or a chatbot, and the failure modes are the ones that only appear once a model is in the loop: leaked system prompts, biased completions, tool calls that reach a database, retrieval that crosses an isolation boundary.
The README lists more than 50 vulnerabilities grouped into Data Privacy, Responsible AI, Security, Safety and Business. The Security group is the interesting one for anyone shipping agents rather than chat: BFLA, BOLA, RBAC bypass, Debug Access, Shell Injection, SQL Injection, SSRF, Tool Metadata Poisoning, Cross-Context Retrieval and System Reconnaissance. Those map to concrete things an agent can be tricked into doing, not to tone problems.
The audience is a Python team that owns the system under test. You supply the model callback and the adversarial inputs; DeepTeam supplies the attack generation and the judging. If you have no code access and only a chat window, you are outside the intended use.
The mechanism: attacks in, LLM-as-a-Judge metrics out
DeepTeam is built on DeepEval, the evaluation framework from the same maintainers, and the dependency is declared in pyproject.toml as deepeval >= 3.6.2. That inheritance explains the shape of the tool. DeepEval gives you metrics that score a model output; DeepTeam adds attacks that try to produce a bad output in the first place.
Each vulnerability is scored by an LLM-as-a-Judge metric. The README states these metrics "run locally on your machine to produce binary pass/fail scores with reasoning". Binary is the important word. You do not get a 0 to 1 risk score to tune a threshold against. You get a pass or a fail plus a written justification, and the justification is what you read when deciding whether the failure is real.
Because the judge is an LLM, the framework needs a model. The README says the vulnerabilities are "powered by ANY LLM of your choice", so the judge is a configuration decision, not a fixed component. That is also the main cost driver: every attack and every judged response is a model call, so a broad run against a large vulnerability list is a token bill, not a CPU job. The pyproject.toml pins openai >= 1.76.2 as a base dependency, and the optional extras (codex, claude-code, cursor) pull in agent SDKs for the code-scanning harnesses.
Installing DeepTeam and running a first red teaming pass
The package is published as deepteam and the project metadata declares python = ">=3.9,<3.14". Install it with pip:
pip install deepteamThe console entry point is declared in pyproject.toml as deepteam = "deepteam.cli.main:app", so a deepteam command is available after install. The v0.1.9 release notes announced a new CLI tool alongside agentic red teaming, and the repository ships example configuration under examples/example_config.yaml and examples/.deepteam-code-scan.yaml.
For a first run, follow the README quickstart rather than guessing at a call signature. The shape is a target model callback plus the vulnerabilities you want checked, and the README is the place to copy the exact call from. Start with two vulnerabilities rather than twenty. A narrow first run tells you whether your judge model is producing sensible reasoning before you spend tokens on the full list.
The code-scanning harnesses are a separate install. The pyproject.toml extras group named harnesses pulls in openai-codex, claude-agent-sdk and cursor-sdk, each requiring Python >=3.10, and examples/code_scan_harness_example.py shows the intended wiring. If you are on Python 3.9, that path is closed to you and only the core library is available.
Where DeepTeam stops being the right tool
The judge is an LLM, so the results are only as good as the judge. A weak or poorly prompted judge model will produce confident reasoning attached to the wrong verdict, and the framework gives you no ground-truth set to calibrate against. DeepTeam does not ship a labelled corpus of known-vulnerable and known-safe responses, so there is no built-in way to measure your judge's false positive rate. You either trust the reasoning text or you build your own validation set.
Second, this is not a scanner you point at a black box. The target in the quickstart is your own model callback. If your agent lives behind a vendor API and you cannot wrap it in a Python function, DeepTeam's value drops sharply. The Security vulnerabilities assume the agent has tools, retrieval or authorization logic to attack; against a plain completion endpoint, most of that group has nothing to bite on.
Third, the README notes the tool "runs locally on your machine", which is a privacy property and an operational burden at the same time. Nothing is uploaded to a service, but nothing is scheduled for you either. The README does not document a CI recipe, and it does not document rollback or baseline diffing between runs, so tracking whether a fix actually closed a finding is left to you.
DeepTeam versus DeepEval, and versus a manual pentest
The comparison people actually search for is deepteam vs deepeval, and the honest answer is that they are layers, not rivals. DeepEval is the evaluation framework: you write test cases, attach metrics, and score outputs for qualities like correctness or faithfulness. DeepTeam imports deepeval and adds the adversarial half, generating the inputs designed to break the system and judging the responses against vulnerability-specific criteria. If you already have a DeepEval suite, DeepTeam is an additional metric family rather than a replacement stack.
The other alternative is a human red team engagement. A consultant brings judgement about your specific product, finds chained exploits no fixed vulnerability list anticipates, and hands you a report. DeepTeam brings repeatability: the same vulnerability list, the same attack generation, run again after every change. It will not find the novel multi-step exploit that a creative tester finds. It will find the PII leak you reintroduced in last week's prompt change, every week, without a calendar invite. Teams that need audit evidence usually want both, and DeepTeam is the cheap half.
Maintenance, licence and upgrade cost
The repository is not archived and the last push was on 2026-08-21. The most recent release listed is v1.0.9, tagged as the first stable release, dated 2025-11-12. The version in pyproject.toml matches at 1.0.9, so the published metadata is in step with the release tag.
The licence is Apache-2.0, declared both in pyproject.toml and in the LICENSE.md file at the repository root. Apache-2.0 permits commercial use and modification and includes a patent grant; it also requires that you preserve notices and state changes. That is a summary of the licence text, not legal advice, and if you redistribute DeepTeam inside a product you should read LICENSE.md rather than this paragraph.
The upgrade cost sits mostly in the dependency tree. deepeval is pinned at >= 3.6.2 with no upper bound, and deepeval is where the metrics are implemented, so a major DeepEval release can change judging behaviour underneath a DeepTeam version you have not touched. The optional harness extras are declared with version "*", which means an install of the harnesses group resolves to whatever is current at install time. Pin your lockfile if you care about reproducible red team runs.
Frequently asked questions about DeepTeam
The questions below are the ones the project's own documentation answers most directly. Anything the README and repository files are silent on, such as judge-model accuracy or CI scheduling, is left out rather than guessed at.
Editorial conclusion
Adopt DeepTeam if your team already runs DeepEval-style tests in Python and wants vulnerability checks such as PII Leakage, Bias or SQL Injection wired into that workflow, with a judge model you choose. Do not adopt it if you need a hosted scanner, a signed pentest report, or a tool that works without an LLM judge. Verify two things first: that your Python version falls inside the declared range of 3.9 to below 3.14, and that the judge model you intend to use is one you are willing to send your adversarial prompts and target outputs to, because the metrics run locally but the model call does not.
Frequently asked questions
What is red teaming LLMs?
It is adversarial testing of a language model system, the LLM equivalent of penetration testing. DeepTeam describes its own work this way and simulates attacks such as jailbreaking, prompt injection and multi-turn exploitation to surface vulnerabilities like bias, PII leakage and SQL injection.
What is the best AI model for red teaming with DeepTeam?
DeepTeam does not name a preferred model. The README states that the 50+ vulnerabilities are powered by any LLM of your choice, and that the LLM-as-a-Judge metrics run locally on your machine to produce binary pass/fail scores with reasoning.
What are the alternatives to DeepTeam?
The README positions DeepTeam as built on DeepEval, the open source LLM evaluation framework from the same maintainers, so DeepEval is the adjacent tool rather than a substitute. A manual red team engagement covers ground a fixed vulnerability list does not, but it is not repeatable on every code change the way DeepTeam is.
What is the best open source LLM model for pentesting?
The README does not recommend a specific open source model. It states only that the vulnerabilities are powered by any LLM of your choice, so the judge model is a configuration decision you make rather than one the project makes for you.
What is the role of a red teamer?
DeepTeam frames its own work as penetration testing for LLM systems: simulating attacks such as jailbreaking, prompt injection and multi-turn exploitation to uncover vulnerabilities like bias, PII leakage and SQL injection. In this tool's model, the person running it supplies the target and the judge model, and reads the pass/fail reasoning the metrics return.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/confident-ai-deepteam)