Skip to content

Latest commit

 

History

9 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

DodoGuard

English | 简体中文

DodoGuard

Your agent passed the demo. It hasn’t passed security.

Evaluate quality · Red-team behavior · Assess Dify / Coze / FastGPT / n8n · Ship with evidence
CLI · Web console · Desktop — run it on your side

Quick start · Docs · Examples · Security

DodoGuard product


What you can catch

Risk What it looks like
Injection & jailbreaks System prompts and guardrails get bypassed
Data & tool abuse Sensitive leaks, unauthorized tool / MCP calls
Regressions Quality drops after a model or prompt change
Platform gaps Misconfig and attack surface on agent apps
Weak release proof No durable findings or reports you can keep private

From check → release → observe

Most teams still spot-check chat. Production agents need a loop:

Evaluate → Attack → Decide → Keep private

Lifecycle: intake → detect & release → observe. Principle: acknowledge ≠ release.

DodoGuard lifecycle

See it in the product

1. Overview

Risk posture across agents and tasks at a glance.

Dashboard

2. Asset ledger

Register agents as assets. Acknowledge ≠ release.

Assets

3. Detection tasks

Run eval, red-team, and platform checks as versioned work.

Tasks

4. Findings

Drill into failures, evidence, and severity.

Task detail

5. Reports

Export release evidence without leaving your infra.

Report

6. Remediation loop

Fix, retest, then decide go-live.

Risk loop

Capabilities at a glance

  • LLM evaluation — prompts, providers, variable cases, multiple assertion types
  • Red-team testing — plugins and adaptive probes on live apps, not only models
  • Platform hardening — Dify-class scans, config audits, risk analysis
  • Ops console — agents, tasks, vulns, remediation, reporting
  • Self-hosted — CLI, Docker, CI/CD, Electron desktop

Providers: OpenAI · Anthropic · Azure · Bedrock · Ollama · OpenAI-compatible APIs


Quick start

CLI — about 60 seconds

Requires Node.js 22.12+.

git clone https://github.com/dodoguardai/dodoguard.git
cd dodoguard && npm ci && npm run build

cp -R examples/openai-eval-factuality ./my-eval && cd my-eval
export OPENAI_API_KEY="<your-api-key>"
../node_modules/.bin/dodoguard eval

More configs: examples/ · local models: examples/redteam-ollama/

Web UI — Docker Compose

docker compose up -d --build
# open http://localhost:3000

Also available

Local development · docker-compose.yml

Never commit API keys, production URLs, or real business data.


Security & contributing

Report vulnerabilities privately via SECURITY.md.
Contribute with CONTRIBUTING.md · Code of Conduct · Support

License

MIT

About

DodoGuard: Full‑lifecycle agent security for Dify, Coze, FastGPT, n8n, Tencent ADP, ByteDance HiAgent, and more.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

202 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages