Skip to content

Red teaming and evaluation · #1 by signal score

Promptfoo

Open-source red teaming, static scanning, and evaluation for LLM applications and agents, with plugins for tool misuse, MCP, memory poisoning, and prompt injection. OpenAI agreed to acquire it in March 2026 and committed to keep it open source.

Acquired by OpenAI, announced 2026-03-09, not yet closed.

31Signal score / 100
Capital
6/35
Product
15/25
Standards
0/20(not yet assessed)
Momentum
10/20

Identity primitives

Agent as a first-class identityNot checked
On-behalf-of token exchangeNot checked
Cross App Access (ID-JAG)Not checked
Asynchronous human approval (CIBA)Not checked
MCP authorization conformanceNot checked
Fine-grained authorizationNot checked
Short-lived, secretless credentialsNot checked
Token vaultNot checked
Kill switchNo public claim found
Per-action audit chainNo public claim found

Threats it says it addresses

Company

HQ: US
Founded: 2024
Funding: $23M disclosed, latest Series A
Product: Promptfoo

Open source

25,404 stars · 350 contributors
Last push 2026-09-24

Sources

  1. Promptfoo red teaming documentation (vendor, accessed 2026-09-24)
  2. Promptfoo: OWASP Top 10 for Agentic Applications (vendor, accessed 2026-09-24)
  3. Promptfoo: OWASP LLM Top 10 (vendor, accessed 2026-09-24)
  4. Promptfoo raises $18.4 million Series A to build definitive AI security stack (press-release, accessed 2026-09-24)
  5. OpenAI acquires Promptfoo to secure its AI agents (trade-press, accessed 2026-09-24)
  6. Promptfoo is joining OpenAI (press-release, accessed 2026-09-24)

Last verified 2026-09-24.