Your agent passed the demo. It hasn’t passed security.
Evaluate quality · Red-team behavior · Assess Dify / Coze / FastGPT / n8n · Ship with evidence
CLI · Web console · Desktop — run it on your side
Quick start · Docs · Examples · Security
| Risk | What it looks like |
|---|---|
| Injection & jailbreaks | System prompts and guardrails get bypassed |
| Data & tool abuse | Sensitive leaks, unauthorized tool / MCP calls |
| Regressions | Quality drops after a model or prompt change |
| Platform gaps | Misconfig and attack surface on agent apps |
| Weak release proof | No durable findings or reports you can keep private |
Most teams still spot-check chat. Production agents need a loop:
Evaluate → Attack → Decide → Keep private
Lifecycle: intake → detect & release → observe. Principle: acknowledge ≠ release.
Risk posture across agents and tasks at a glance.
Register agents as assets. Acknowledge ≠ release.
Run eval, red-team, and platform checks as versioned work.
Drill into failures, evidence, and severity.
Export release evidence without leaving your infra.
Fix, retest, then decide go-live.
- LLM evaluation — prompts, providers, variable cases, multiple assertion types
- Red-team testing — plugins and adaptive probes on live apps, not only models
- Platform hardening — Dify-class scans, config audits, risk analysis
- Ops console — agents, tasks, vulns, remediation, reporting
- Self-hosted — CLI, Docker, CI/CD, Electron desktop
Providers: OpenAI · Anthropic · Azure · Bedrock · Ollama · OpenAI-compatible APIs
Requires Node.js 22.12+.
git clone https://github.com/dodoguardai/dodoguard.git
cd dodoguard && npm ci && npm run build
cp -R examples/openai-eval-factuality ./my-eval && cd my-eval
export OPENAI_API_KEY="<your-api-key>"
../node_modules/.bin/dodoguard evalMore configs: examples/ · local models: examples/redteam-ollama/
docker compose up -d --build
# open http://localhost:3000Local development · docker-compose.yml
Never commit API keys, production URLs, or real business data.
Report vulnerabilities privately via SECURITY.md.
Contribute with CONTRIBUTING.md · Code of Conduct · Support








