Highlights
- DeepTeam is a framework, Agent OPFOR is a tool: DeepTeam gives you code-level control via Python; Agent OPFOR gives you a working red team in three commands, no harness required.
- Agent OPFOR is the only tool covering all four OWASP suites — LLM, Agentic, MCP, and API.
- Agent OPFOR is also the only one that tests MCP servers at the wire-protocol level, not just through a model callback.
- DeepTeam is the better choice if you need production guardrails — its seven runtime guards block harmful inputs and outputs in live systems; Agent OPFOR is purely offensive.
- Non-developers can use Agent OPFOR via its browser extension — PMs, QA, and security analysts can test any deployed chatbot with no terminal, no YAML, and no config files.
- Most teams benefit from both: Agent OPFOR for fast, broad, anyone-can-run red teaming; DeepTeam for a custom Python pipeline with runtime defense.
AI red teaming is the practice of systematically probing a language model or AI system with adversarial inputs — injections, jailbreaks, data-leakage attempts — to surface security and safety failures before attackers do. Shipping an LLM feature means shipping a new attack surface: prompt injections, a tool call that leaks another user's data, an MCP server that surrenders a token to the right phrasing. Red teaming is how you find those failures first.
Two open-source AI red teaming frameworks (both Apache 2.0) dominate the conversation, and they're easy to confuse. DeepTeam is a Python framework: a library you wire into your own harness, with deep code control and a paid platform (Confident AI) for the UI. Agent OPFOR is a tool: install it, run opfor run, get a report — from a CLI, your IDE, or a browser extension. Building blocks, or a finished product? That's the real choice.
Agent OPFOR vs DeepTeam: Feature Comparison Table
The table below compares Agent OPFOR and DeepTeam across eight key dimensions relevant to AI security teams.
Comparison reflects each project as of June 2026. Both move quickly — DeepTeam in particular ships frequent releases, so guardrail and coverage details may have changed since.
How Agent OPFOR and DeepTeam Generate AI Attacks (and Why It Matters)
This is where the two diverge philosophically, and most of the other differences follow from it.
DeepTeam thinks in vulnerabilities and attacks as code. You import the vulnerability you care about and the technique you want to apply, and the two compose: an attack enhances a baseline probe rather than replacing it. The whole thing is a few lines of Python.
The following example shows the minimum viable DeepTeam setup — importing a vulnerability, applying an attack, and running the assessment in ~10 lines:
from deepteam import red_team
from deepteam.vulnerabilities import Bias
from deepteam.attacks.single_turn import PromptInjection
risk_assessment = red_team(
model_callback=my_llm, # wraps your app: str in, str out
vulnerabilities=[Bias(types=["race"])],
attacks=[PromptInjection()],
)
You never declare what your system is — you hand it a model_callback, and it generates adversarial inputs, judges outputs with an LLM-as-a-judge metric, and returns a risk assessment. No dataset to prepare. It's a clean abstraction, and the right one if you're going to live in code anyway.
Agent OPFOR thinks in declarative attack files. Each check is a rubric plus a fan-out of attack patterns — the prompt-injection evaluator alone expands into dozens of techniques (split-payload, persona-hijack, translation-evasion, and so on). Across the agent surface that's 60-plus evaluators fanning out into 400-plus attack patterns, with a separate tree for MCP-server testing. You don't write code to run any of it; you run a command and the engine reads the files. Contributing a new attack means dropping in one file — lowering the bar for non-programmers, at the cost of the rigor in DeepTeam's research-backed attack classes. Both are reasonable; they optimize for different contributors.
Worth calling out: every Agent OPFOR evaluator ships a co-located pass/fail fixture — one example that should be flagged, one that should be cleared — and CI fails the build if the judge gets either verdict wrong. That turns "the rubric parses" into "the rubric still catches what it claims to," a guard against the slow rot a growing library of LLM-judged checks is prone to. DeepTeam has no per-attack equivalent.
DeepTeam Strengths: Guardrails, Research-Backed Attacks, and Framework Presets
DeepTeam is a serious, actively maintained project, and it earns the reputation. It ships 50+ vulnerabilities across data privacy, responsible AI, security, safety, business, and agentic categories, and 20+ attack methods, single- and multi-turn — prompt injection, roleplay, encoding tricks (leetspeak, ROT13, base64), and linear/tree/crescendo jailbreaking among them. These are implementations of published jailbreak research, not toy probes: an attack that mirrors a technique seen in the wild tells you something a hand-written string can't.
Framework alignment is a real strength. One line — framework=OWASPTop10() — maps a standard's categories onto the right vulnerabilities and attacks automatically, and the same holds for NIST, MITRE, OWASP_ASI_2026, Aegis, and BeaverTails. Both tools map findings to MITRE ATLAS (Agent OPFOR maps many of its evaluators to MITRE ATLAS techniques; DeepTeam ships it as a selectable framework preset), but if your compliance story specifically requires NIST AI RMF — or the Aegis and BeaverTails safety taxonomies — DeepTeam is the one with those built in.
The capability Agent OPFOR has no answer for is guardrails. DeepTeam ships seven production-ready guards — toxicity, prompt injection, privacy, illegal content, hallucination, topical, cybersecurity — for fast binary classification of live inputs and outputs, closing the loop from finding a weakness to blocking it in production. Agent OPFOR doesn't do this at all; worth weighing if you want AI red-teaming and runtime defense in one package.
Built on DeepEval, with an active Discord and frequent releases, DeepTeam is a well-supported foundation. The emphasis is on foundation.
DeepTeam's Framework Tradeoff: What You Build vs What You Get
Everything good about a framework carries the same cost: it gives you parts, and you build the thing. DeepTeam hands back a risk_assessment object as a dataframe or JSON — not a place for it to live, a report you can drop into a review, a way for a non-engineer to run a scan, or a dashboard your security team will open. The README is upfront: "Need a place for your red teaming results to live? Sign up to the Confident AI platform." The UI, production monitoring, shared reports, and run-from-your-IDE experience all live on Confident AI, the maintainers' commercial platform. That's a legitimate model, but it changes the cost of adoption: going from pip install to "a teammate ran a scan and I'm reading the report" means writing that glue yourself or paying for the platform. For a Python team building its own pipeline, that control is the point; for everyone else, it's a project before it's a result.
One coverage detail follows from the architecture: DeepTeam's MCP-related checks — tool metadata poisoning, tool orchestration abuse — run like everything else, adversarial input through your model_callback judged on the text returned. It doesn't speak the MCP wire protocol to a server directly. If your attack surface is an MCP server, that's a real gap.
Agent OPFOR Strengths: CLI, Browser Extension, and MCP Protocol Testing
Agent OPFOR starts where "now build your harness" ends. Three commands get you a report:
npm install -g @keyvaluesystems/agent-opfor-cli
opfor setup # wizard: target, provider, suite, turns
opfor run # generates attacks, fires them, judges, writes HTML + JSON
No callback to write, no dataset, no platform to stand up. Each run lands in its own folder with a self-contained HTML report and a JSON file for CI.
The bigger difference is reach: the same evaluators, attacks, and judge logic run from five entry points.
- CLI: opfor run exits non-zero the moment any check fails, so a red-team scan gates a build the same way a failing test does.
- MCP server: Register Agent OPFOR in Cursor or Claude Desktop and say "red team my chatbot at localhost:4000." Your coding agent drives the run.
- IDE skills: Expose /opfor-setup and /opfor-run inline.
- Browser extension: Open any deployed chatbot, click the icon, pick a suite, and watch it type attacks into the live chat, then download a report. No terminal, no YAML, no keys in a config file.
- TypeScript SDK: Integrate Agent OPFOR's attack engine directly into any TypeScript or Node.js codebase. You get the same evaluators and judge logic as the CLI, callable programmatically without leaving your own toolchain.
On standards, Agent OPFOR is the only tool covering all four OWASP suites — LLM, Agentic, MCP, and API — plus an EU AI Act bias suite and a harmful-content suite from the MLCommons and HarmBench taxonomies. Its MCP testing is protocol-level: it enumerates a server's tools, fires real tools/call requests with adversarial arguments, and scans resources/read for leaked secrets — attacks no model-callback approach can reach. It's trace-aware too (Langfuse, Netra), so the judge sees the tool calls behind a response and catches PII that leaks into a call but never surfaces in the reply.
Two honest caveats: Agent OPFOR has no guardrails — it's purely offensive, so production-time blocking still means DeepTeam or another tool. And it's the younger project, without DeepTeam's track record, community size, or published-research lineage behind its attacks.
Agent OPFOR Autonomous Mode: Objective-Driven Multi-Agent Red Teaming
Agent OPFOR's most ambitious mode turns the workflow inside out. Instead of choosing a suite, you give it a target and a plain-English goal — "see whether the support bot can be talked into a refund it shouldn't give" — and it runs the entire engagement itself, the way a human red team would.
Under the hood, opfor hunt is a small team of cooperating AI agents built on the Claude Agent SDK. A commander scopes the target and draws up a plan; a squad of operators each take one weakness and pursue it through adaptive, multi-turn attacks, grading their own results as they go; and a scout quietly fingerprints the target first. When a probe looks promising, the team branches off to chase the lead; when one stalls, it drops it. It improvises new tactics mid-run and keeps the ones that land. You set a dollar budget — it works up to that ceiling, then writes the report.
DeepTeam's tree jailbreaking is a clever algorithm for sharpening one attack against a vulnerability you name. Autonomous mode is an agent you hand a goal and a budget — the clearest expression of Agent OPFOR's bet that red teaming should be something you run, not something you assemble.
Agent OPFOR vs DeepTeam: Which Should You Choose?
The split is cleaner than most tool comparisons, because the two aren't competing for the same job.
Choose DeepTeam if:
- You're a Python team building your own eval-and-red-team platform and want code-level control over every vulnerability and attack
- You value attacks grounded in published research (50+ vulnerabilities, 20+ attack methods)
- You need NIST AI RMF, Aegis, or BeaverTails compliance presets
- You want production runtime guardrails in the same package as your red-teaming framework
- You're comfortable assembling your own reporting pipeline, or you're willing to adopt Confident AI for the UI
Choose Agent OPFOR if:
- You want to run an AI red team today, without writing a harness
- Non-developers — PMs, QA engineers, security analysts — need to test deployed chatbots themselves
- Your attack surface includes MCP servers you need probed at the wire-protocol level
- You need all four OWASP suites (LLM, Agentic, MCP, API) from one tool
- You want CI/CD that gates builds on any failing check (non-zero exit + JSON artifact)
- You want an autonomous red team you control with a plain-English goal and a dollar budget
Plenty of teams will run both — Agent OPFOR for fast, broad, anyone-can-run coverage and protocol-level MCP testing, DeepTeam for a customized Python pipeline and runtime guardrails. They're two answers to the same threat: one you assemble, one you run.
Try Agent OPFOR → | Explore DeepTeam docs →
FAQ
Is Agent OPFOR free?
Yes. Agent OPFOR is open-source under the Apache 2.0 license with no paid tier.
Is DeepTeam free?
The DeepTeam framework is open-source (Apache 2.0) and free. Its UI, dashboards, production monitoring, and run-from-IDE experience are provided by Confident AI, the maintainers' commercial platform.
Does Agent OPFOR work with any LLM?
Yes. Agent OPFOR works with any LLM you can point a provider key at — including OpenAI, Anthropic, and other providers — configured via its setup wizard.
Can DeepTeam test MCP servers?
Not at the wire-protocol level. DeepTeam's MCP-related checks run adversarial inputs through your model_callback and judge the text returned — it doesn't speak the MCP protocol directly. Agent OPFOR fires real tools/call requests with adversarial arguments and scans resources/read for leaked secrets.
What is the difference between AI red teaming and AI guardrails?
Red teaming is offensive — it finds vulnerabilities by probing the system before deployment. Guardrails are defensive — they classify and block harmful inputs/outputs at runtime in production. DeepTeam provides both. Agent OPFOR provides red teaming only.
Which tool has better OWASP coverage?
Agent OPFOR covers all four OWASP suites: LLM, Agentic, MCP, and API. DeepTeam covers OWASP LLM and OWASP Agents. If you need MCP or API OWASP coverage, Agent OPFOR is currently the only option.
Can a non-developer use either of these tools?
Agent OPFOR yes — its browser extension lets anyone test a deployed chatbot with no terminal, no YAML, and no API keys required. DeepTeam is Python-first and requires coding ability for all workflows.