TOOLS

Promptfoo

Promptfoo is an Open-source LLM red teaming framework. Automated prompt injection scanning, jailbreak testing, and safety validation with customizable attack plugins for quality, security, and reliability.

Promptfoo
1068 words · 6 min

Overview

Promptfoo sits at the intersection of LLM evaluation, adversarial testing, prompt-injection testing, agent security, and RAG validation.

Think of Promptfoo as pytest + benchmark framework + security scanner for LLM applications.

It lets you define:

INPUTS
   │
   ├── Prompt A ──► Model A
   ├── Prompt A ──► Model B
   ├── Prompt B ──► Model A
   └── Prompt B ──► Model B
             │
             ▼
       Assertions / Graders
             │
             ▼
       PASS / FAIL / SCORE

And for security:

Promptfoo
   │
   ├── Prompt injection
   ├── Jailbreaks
   ├── Data leakage
   ├── RAG poisoning
   ├── Excessive agency
   ├── System prompt extraction
   ├── Harmful-content tests
   └── Custom security policies
             │
             ▼
        Your LLM / Agent / RAG

Promptfoo specifically supports automated evaluation of prompts, models, RAG pipelines and agents, alongside automated red teaming and CI/CD integration.

Installation

Note
  • Based on CachyOS/Arch Linux
  • Promptfoo currently requires Node.js 22.22.0 or newer.

Update CachyOS and install Node.js 24 LTS + npm

$ sudo pacman -Syu
$ sudo pacman -S nodejs-lts-krypton npm
$ node --version
$ npm --version

Install some useful development dependencies

$ sudo pacman -S --needed \
    git \
    python \
    python-pip \
    jq \
    curl \
    ripgrep \
    base-devel

Configure npm for our user

$ mkdir -p ~/.local/bin
$ mkdir -p ~/.local/lib
$ npm config set prefix "$HOME/.local"
$ fish_add_path -m ~/.local/bin

# Or if you use Bash
$ echo 'export PATH="$HOME/.local/bin:$PATH"' >> ~/.bashrc
$ source ~/.bashrc

# Or if you use Zsh
$ echo 'export PATH="$HOME/.local/bin:$PATH"' >> ~/.zshrc
$ source ~/.zshrc

$ npm config get prefix

Install Promptfoo

$ npm install -g promptfoo
$ promptfoo --version
$ which promptfoo

Check Promptfoo

$ promptfoo --help
$ promptfoo --version
$ promptfoo redteam --help
$ promptfoo redteam plugins

Create our Promptfoo workspace

$ mkdir -p ~/labs/promptfoo
$ cd ~/labs/promptfoo
$ promptfoo init
$ cd ~/labs
$ promptfoo init --example getting-started
$ cd getting-started
$ ls -la

Configure OpenAI (If you have an OpenAI API key)

$ export OPENAI_API_KEY="YOUR_API_KEY"
$ test -n "$OPENAI_API_KEY" && echo "OPENAI_API_KEY is set"

For persistence, we recommend using a .env file inside the project, rather than putting the key directly into YAML:

$ nano .env

Put:

OPENAI_API_KEY=YOUR_API_KEY

Then:

$ chmod 600 .env

And make sure Git doesn’t accidentally commit it:

$ echo ".env" >> .gitignore

Promptfoo supports .env files and the --env-file option.

First evaluation

$ cd ~/labs/getting-started
$ promptfoo eval
$ promptfoo view

This gives you the web-based evaluation interface.

Install Ollama

For our security research, we also install Ollama so we can test local models without sending everything to an API provider.

$ sudo pacman -S ollama
$ sudo systemctl enable --now ollama
$ systemctl status ollama
$ ollama --version
$ ollama pull llama3.3
$ ollama list
$ ollama run llama3.3
$ /bye

Test OpenAI + Ollama side-by-side

Create

$ nano promptfooconfig.yaml

For example:

description: WE ARE THE BUG - basic LLM evaluation

prompts:
  - |
    You are a cybersecurity research assistant.

    Answer the following question accurately and concisely:

    {{question}}

providers:
  - openai:gpt-5
  - ollama:chat:llama3.3

tests:
  - vars:
      question: "What is Kerberoasting?"
    assert:
      - type: contains
        value: "Kerberos"

  - vars:
      question: "What is prompt injection?"
    assert:
      - type: contains
        value: "instruction"

  - vars:
      question: "Explain the principle of least privilege."
    assert:
      - type: contains
        value: "privilege"

Run

$ promptfoo eval

Currently we have:

                 SAME TEST
                    │
          ┌─────────┴─────────┐
          ▼                   ▼
       GPT-5              Llama 3.3
          │                   │
          └─────────┬─────────┘
                    ▼
                Assertions
                    │
                    ▼
                 Results

That’s our first model benchmark.

Add Anthropic

If you have an Anthropic API key:

$ nano .env

Add:

ANTHROPIC_API_KEY=YOUR_API_KEY

Then add another provider:

providers:
  - openai:gpt-5
  - anthropic:messages:claude-sonnet-5
  - ollama:chat:llama3.3

And then let’s evaluate:

$ promptfoo eval

So we have compare:

                 TEST SUITE
                     │
       ┌─────────────┼─────────────┐
       ▼             ▼             ▼
      GPT          Claude        Ollama
       │             │             │
       └─────────────┼─────────────┘
                     ▼
                 Evaluation

Plugins

Now we install/use some interesting plugins.

Promptfoo red-team plugins are part of the red-team framework.

List them:

$ promptfoo redteam plugins

For our lab. we can initially concentrate on:

prompt-injection
jailbreak
pii
excessive-agency
hijacking
hallucination
overreliance
RAG poisoning
data leakage

Obtain the IDs supported by our installed version (exact plugin IDs can change between Promptfoo versions):

$ promptfoo redteam plugins

First red-team project

$ cd ~/labs
$ promptfoo redteam init ai-security-lab --no-gui
$ cd ai-security-lab
$ ls -la

Follow the workflow.

Run the red-team scan:

$ promptfoo redteam run

Read the report:

$ promptfoo redteam report

We can explicitly select plugins.

For example:

$ promptfoo redteam generate \
  --plugins "hijacking,excessive-agency,hallucination,pii"
$ promptfoo redteam run  

Do not forget that the exact plugin IDs available to you should be checked first:

$ promptfoo redteam plugins

For many tests, we recommand to create a similar directory structure:

~/labs/promptfoo/
│
├── prompts/
│   ├── system-v1.txt
│   ├── system-v2.txt
│   └── security-agent.txt
│
├── evaluations/
│   ├── accuracy/
│   ├── regression/
│   └── model-comparison/
│
├── rag/
│   ├── retrieval/
│   ├── grounding/
│   └── poisoning/
│
├── agents/
│   ├── tool-use/
│   ├── permissions/
│   └── trajectories/
│
├── redteam/
│   ├── injection/
│   ├── jailbreak/
│   ├── leakage/
│   └── agency/
│
└── README.md
Note
  • TARGET is different than ATTACK GENERATOR / GRADER
  • Promptfoo’s current red-team implementation can use your configured OpenAI key for attack generation/grading.
    • If you don’t provide one, its remote generation service can be used. -Target evaluation itself runs locally.

For example:

                  Promptfoo
                     │
          ┌──────────┴──────────┐
          ▼                     ▼
     Attack model          Target model
          │                     │
          ▼                     ▼
    Generate attack        Your AI
          │                     │
          └──────────┬──────────┘
                     ▼
                  Grader

Optional

Python agent/RAG integration

Because you’re likely to eventually test Python-based agents/RAG pipelines, make sure Python is available:

$ python --version

Create a virtual environment and then activate it:

$ python -m venv ~/labs/promptfoo/.venv
$ source ~/labs/promptfoo/.venv/bin/activate

If needed, Install/Upgrade pip:

$ pip install --upgrade pip

Then you can install whatever RAG/agent framework you’re testing without polluting the CachyOS system Python.

Promptfoo supports custom Python providers such as:

providers:
  - file://provider.py

Example of eventual architecture:

Promptfoo
    │
    ▼
provider.py
    │
    ▼
Your Python Agent
    │
    ├── LLM
    ├── RAG
    ├── Vector DB
    └── Tools

Git repository

$ cd ~/labs/promptfoo
$ git init

Create:

$ nano .gitignore

Put:

.env
*.log
node_modules/
.promptfoo/
.venv/
__pycache__/

Then:

$ git add .
$ git commit -m "Initial Promptfoo AI security lab"

Some other examples

If all above works, then we are ready for the Promptfoo evaluation + model comparison + RAG testing + agent testing + AI red-team workflow.

We will continue to update here with practical examples and use cases…

Also Promptfoo is joining OpenAI.