---
title: "deer-flow vs agentdojo"
type: "comparison"
canonical_url: "https://www.graphcanon.com/compare/bytedance-deer-flow-vs-ethz-spylab-agentdojo"
tools: ["bytedance-deer-flow", "ethz-spylab-agentdojo"]
---

# deer-flow vs agentdojo

*GraphCanon updated Aug 16, 2026*

## Verdict

Pick deer-flow if deer-flow is an advanced SuperAgent platform for handling complex tasks over extended periods with a comprehensive set of functionalities such as sandboxes and memories; pick agentdojo if agentDojo serves as a benchmarking environment to evaluate security attacks, like prompt injection, and defenses for Large Language Model (LLM) agents.

[deer-flow](https://deerflow.tech) reports 80k GitHub stars, 11k forks, and 948 open issues, last pushed Aug 16, 2026. [agentdojo](https://agentdojo.spylab.ai/) has 716 stars, 188 forks, and 41 open issues, last pushed Jun 2, 2026. Figures are from public GitHub metadata via [deer-flow's repository](https://github.com/bytedance/deer-flow) and [agentdojo's repository](https://github.com/ethz-spylab/agentdojo).

| | [deer-flow](/tools/bytedance-deer-flow.md) | [agentdojo](/tools/ethz-spylab-agentdojo.md) |
| --- | --- | --- |
| Tagline | An open-source long-horizon SuperAgent that handles complex tasks over minutes to hours. | A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents |
| Stars | 80,066 | 716 |
| Forks | 10,961 | 188 |
| Open issues | 948 | 41 |
| Language | Python | Python |
| Adopt for | Deer-flow is an advanced SuperAgent platform for handling complex tasks over extended periods with a comprehensive set of functionalities such as sandboxes and memories. | AgentDojo serves as a benchmarking environment to evaluate security attacks, like prompt injection, and defenses for Large Language Model (LLM) agents. |
| Persona | - | - |
| Runtime | - | - |
| License | MIT | MIT |
| Categories | AI Agents | AI Agents, Evaluation & Observability |

## Trust and health

_Sourced signals - not a safety guarantee. No winner column._

| | [deer-flow](/tools/bytedance-deer-flow.md) | [agentdojo](/tools/ethz-spylab-agentdojo.md) |
| --- | --- | --- |
| Maintenance | Very active (96%) | Steady (60%) |
| Days since push | 0d | 63d |
| Open issues (now) | 948 | 41 |
| Stars delta | +2.9k (30d) | Unknown |
| Open issues delta | -29 (30d) | Unknown |
| Full report | [trust report](/tools/bytedance-deer-flow/trust.md) | [trust report](/tools/ethz-spylab-agentdojo/trust.md) |

## Decision facts: deer-flow

- **Adopt for:** Deer-flow is an advanced SuperAgent platform for handling complex tasks over extended periods with a comprehensive set of functionalities such as sandboxes and memories.

## Decision facts: agentdojo

- **Pricing:** freemium - Open-source under the MIT License. Some advanced features might require additional libraries or APIs.
- **Requirements:** Min 8 GB RAM
- **Adopt for:** AgentDojo serves as a benchmarking environment to evaluate security attacks, like prompt injection, and defenses for Large Language Model (LLM) agents.

## Choose when

### Choose deer-flow if…

- Tags unique to deer-flow: agent, agentic-framework, ai-agents, langchain.
- When you need to manage lengthy workflows over minutes to hours that require constant supervision or adaptation by the AI agent, deer-flow's long-horizon capabilities make it suitable.
- More GitHub stars (80k vs 716) - visibility, not fit.

### Choose agentdojo if…

- Pricing: Open-source under the MIT License. Some advanced features might require additional libraries or APIs..
- Requirements: Min 8 GB RAM.
- Tags unique to agentdojo: benchmark, large language models, prompt-injection, security.
- Also covers Evaluation & Observability.
- AgentDojo serves as a benchmarking environment to evaluate security attacks, like prompt injection, and defenses for Large Language Model (LLM) agents.

## When NOT to use deer-flow

- For short, straightforward tasks that do not require extensive workflows (under a minute), deer-flow might be overkill due to its advanced functionalities and setup complexity.
- If your team is primarily working with technologies like Node.js or TypeScript rather than Python, other tools might offer better integration and support.

## When NOT to use agentdojo

- AI Agents: Don't use an agent loop when a deterministic workflow would do; agents add latency, cost, and non-determinism.
- Evaluation & Observability: Defer heavyweight eval infra only until you have real traffic - never skip it once users depend on answers.

## Common questions

### What is the difference between deer-flow and agentdojo?

deer-flow: An open-source long-horizon SuperAgent that handles complex tasks over minutes to hours.. agentdojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents. See the comparison table for live GitHub stats and shared categories.

### When should I choose deer-flow over agentdojo?

Choose deer-flow over agentdojo when Tags unique to deer-flow: agent, agentic-framework, ai-agents, langchain; When you need to manage lengthy workflows over minutes to hours that require constant supervision or adaptation by the AI agent, deer-flow's long-horizon capabilities make it suitable; More GitHub stars (80k vs 716) - visibility, not fit.

### When should I choose agentdojo over deer-flow?

Choose agentdojo over deer-flow when Pricing: Open-source under the MIT License. Some advanced features might require additional libraries or APIs.; Requirements: Min 8 GB RAM; Tags unique to agentdojo: benchmark, large language models, prompt-injection, security; Also covers Evaluation & Observability; AgentDojo serves as a benchmarking environment to evaluate security attacks, like prompt injection, and defenses for Large Language Model (LLM) agents.

### When should I avoid deer-flow?

For short, straightforward tasks that do not require extensive workflows (under a minute), deer-flow might be overkill due to its advanced functionalities and setup complexity. If your team is primarily working with technologies like Node.js or TypeScript rather than Python, other tools might offer better integration and support.

### When should I avoid agentdojo?

AI Agents: Don't use an agent loop when a deterministic workflow would do; agents add latency, cost, and non-determinism. Evaluation & Observability: Defer heavyweight eval infra only until you have real traffic - never skip it once users depend on answers.

### Is deer-flow or agentdojo more popular on GitHub?

deer-flow has more GitHub stars (80,066 vs 716). Stars measure visibility, not whether either tool fits your constraints.

### Are deer-flow and agentdojo open source?

Yes - both are open-source projects on GitHub (deer-flow: MIT, agentdojo: MIT).

### Where can I find alternatives to deer-flow or agentdojo?

GraphCanon lists graph-backed alternatives at [deer-flow alternatives](/tools/bytedance-deer-flow/alternatives) and [agentdojo alternatives](/tools/ethz-spylab-agentdojo/alternatives) ([deer-flow markdown twin](/tools/bytedance-deer-flow/alternatives.md), [agentdojo markdown twin](/tools/ethz-spylab-agentdojo/alternatives.md)), ranked by typed relationship edges rather than popularity votes.

### Is there a machine-readable version of this comparison?

Yes. The markdown twin at [this comparison](/compare/bytedance-deer-flow-vs-ethz-spylab-agentdojo.md) mirrors this page for agents and LLM crawlers, with the same stats table and FAQ answers.

### Which is better maintained, deer-flow or agentdojo?

deer-flow: Very active. agentdojo: Steady. Compare maintenance labels, days since push, and release cadence in the trust section below - stars alone do not measure maintenance.

### Where are the full trust reports for deer-flow and agentdojo?

GraphCanon publishes per-repo trust reports with dated maintenance, provenance, and scan summaries: [deer-flow trust report](/tools/bytedance-deer-flow/trust); [agentdojo trust report](/tools/ethz-spylab-agentdojo/trust).

---

**Machine-readable endpoints**

- JSON: [`/api/graphcanon/graph?tool=bytedance-deer-flow`](/api/graphcanon/graph?tool=bytedance-deer-flow)
- LLM index: [/llms.txt](/llms.txt)
- Full corpus: [/llms-full.txt](/llms-full.txt)

_GraphCanon - The knowledge graph for AI development. https://www.graphcanon.com/_
