---
title: "agentdojo vs PromptAttack"
type: "comparison"
canonical_url: "https://www.graphcanon.com/compare/ethz-spylab-agentdojo-vs-godxuxilie-promptattack"
tools: ["ethz-spylab-agentdojo", "godxuxilie-promptattack"]
---

# agentdojo vs PromptAttack

*GraphCanon updated Aug 5, 2026*

## Verdict

Pick agentdojo if agentDojo serves as a benchmarking environment to evaluate security attacks, like prompt injection, and defenses for Large Language Model (LLM) agents; pick PromptAttack if promptAttack is an LLM-targeted adversarial attack tool that leverages prompt engineering to generate adversarial samples keeping semantic intact but misclassifying outputs.

[agentdojo](https://agentdojo.spylab.ai/) reports 716 GitHub stars, 188 forks, and 41 open issues, last pushed Jun 2, 2026. [PromptAttack](https://github.com/GodXuxilie/PromptAttack) has 117 stars, 17 forks, and 0 open issues, last pushed Jan 21, 2025. Figures are from public GitHub metadata via [agentdojo's repository](https://github.com/ethz-spylab/agentdojo) and [PromptAttack's repository](https://github.com/GodXuxilie/PromptAttack).

| | [agentdojo](/tools/ethz-spylab-agentdojo.md) | [PromptAttack](/tools/godxuxilie-promptattack.md) |
| --- | --- | --- |
| Tagline | A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents | An LLM can Fool Itself: A Prompt-Based Adversarial Attack |
| Stars | 716 | 117 |
| Forks | 188 | 17 |
| Open issues | 41 | 0 |
| Language | Python | Python |
| Adopt for | AgentDojo serves as a benchmarking environment to evaluate security attacks, like prompt injection, and defenses for Large Language Model (LLM) agents. | PromptAttack is an LLM-targeted adversarial attack tool that leverages prompt engineering to generate adversarial samples keeping semantic intact but misclassifying outputs. |
| Persona | - | - |
| Runtime | - | - |
| License | MIT | - |
| Categories | AI Agents, Evaluation & Observability | Evaluation & Observability |

## Trust and health

_Sourced signals - not a safety guarantee. No winner column._

| | [agentdojo](/tools/ethz-spylab-agentdojo.md) | [PromptAttack](/tools/godxuxilie-promptattack.md) |
| --- | --- | --- |
| Maintenance | Steady (60%) | Dormant (18%) |
| Days since push | 63d | 560d |
| Open issues (now) | 41 | 0 |
| Owner type | Organization | User |
| Full report | [trust report](/tools/ethz-spylab-agentdojo/trust.md) | [trust report](/tools/godxuxilie-promptattack/trust.md) |

## Shared compatibility

- **Python**: [agentdojo](/tools/ethz-spylab-agentdojo.md) - Python runtime; [PromptAttack](/tools/godxuxilie-promptattack.md) - Python runtime

## Decision facts: agentdojo

- **Pricing:** freemium - Open-source under the MIT License. Some advanced features might require additional libraries or APIs.
- **Requirements:** Min 8 GB RAM
- **Adopt for:** AgentDojo serves as a benchmarking environment to evaluate security attacks, like prompt injection, and defenses for Large Language Model (LLM) agents.

## Decision facts: PromptAttack

- **Adopt for:** PromptAttack is an LLM-targeted adversarial attack tool that leverages prompt engineering to generate adversarial samples keeping semantic intact but misclassifying outputs.

## Choose when

### Choose agentdojo if…

- Pricing: Open-source under the MIT License. Some advanced features might require additional libraries or APIs..
- Requirements: Min 8 GB RAM.
- Tags unique to agentdojo: benchmark, large language models, prompt-injection, security.
- Also covers AI Agents.
- AgentDojo serves as a benchmarking environment to evaluate security attacks, like prompt injection, and defenses for Large Language Model (LLM) agents.

### Choose PromptAttack if…

- Tags unique to PromptAttack: adversarial attack, language model evaluation, prompt-engineering.
- For targeted analysis of adversarial robustness in specific language models.
- Leaner open-issue backlog (0).

## When NOT to use agentdojo

- AI Agents: Don't use an agent loop when a deterministic workflow would do; agents add latency, cost, and non-determinism.
- Evaluation & Observability: Defer heavyweight eval infra only until you have real traffic - never skip it once users depend on answers.

## When NOT to use PromptAttack

- If the focus is on general model improvement rather than adversarial testing.
- When working with proprietary or sensitive data that cannot be manipulated via external prompt tools, given potential data leakage concerns.

## Common questions

### What is the difference between agentdojo and PromptAttack?

agentdojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents. PromptAttack: An LLM can Fool Itself: A Prompt-Based Adversarial Attack. See the comparison table for live GitHub stats and shared categories.

### When should I choose agentdojo over PromptAttack?

Choose agentdojo over PromptAttack when Pricing: Open-source under the MIT License. Some advanced features might require additional libraries or APIs.; Requirements: Min 8 GB RAM; Tags unique to agentdojo: benchmark, large language models, prompt-injection, security; Also covers AI Agents; AgentDojo serves as a benchmarking environment to evaluate security attacks, like prompt injection, and defenses for Large Language Model (LLM) agents.

### When should I choose PromptAttack over agentdojo?

Choose PromptAttack over agentdojo when Tags unique to PromptAttack: adversarial attack, language model evaluation, prompt-engineering; For targeted analysis of adversarial robustness in specific language models; Leaner open-issue backlog (0).

### When should I avoid agentdojo?

AI Agents: Don't use an agent loop when a deterministic workflow would do; agents add latency, cost, and non-determinism. Evaluation & Observability: Defer heavyweight eval infra only until you have real traffic - never skip it once users depend on answers.

### When should I avoid PromptAttack?

If the focus is on general model improvement rather than adversarial testing. When working with proprietary or sensitive data that cannot be manipulated via external prompt tools, given potential data leakage concerns.

### Is agentdojo or PromptAttack more popular on GitHub?

agentdojo has more GitHub stars (716 vs 117). Stars measure visibility, not whether either tool fits your constraints.

### Are agentdojo and PromptAttack open source?

Yes - both are open-source projects on GitHub.

### Where can I find alternatives to agentdojo or PromptAttack?

GraphCanon lists graph-backed alternatives at [agentdojo alternatives](/tools/ethz-spylab-agentdojo/alternatives) and [PromptAttack alternatives](/tools/godxuxilie-promptattack/alternatives) ([agentdojo markdown twin](/tools/ethz-spylab-agentdojo/alternatives.md), [PromptAttack markdown twin](/tools/godxuxilie-promptattack/alternatives.md)), ranked by typed relationship edges rather than popularity votes.

### Is there a machine-readable version of this comparison?

Yes. The markdown twin at [this comparison](/compare/ethz-spylab-agentdojo-vs-godxuxilie-promptattack.md) mirrors this page for agents and LLM crawlers, with the same stats table and FAQ answers.

### Which is better maintained, agentdojo or PromptAttack?

agentdojo: Steady. PromptAttack: Dormant. Compare maintenance labels, days since push, and release cadence in the trust section below - stars alone do not measure maintenance.

### Where are the full trust reports for agentdojo and PromptAttack?

GraphCanon publishes per-repo trust reports with dated maintenance, provenance, and scan summaries: [agentdojo trust report](/tools/ethz-spylab-agentdojo/trust); [PromptAttack trust report](/tools/godxuxilie-promptattack/trust).

---

**Machine-readable endpoints**

- JSON: [`/api/graphcanon/graph?tool=ethz-spylab-agentdojo`](/api/graphcanon/graph?tool=ethz-spylab-agentdojo)
- LLM index: [/llms.txt](/llms.txt)
- Full corpus: [/llms-full.txt](/llms-full.txt)

_GraphCanon - The knowledge graph for AI development. https://www.graphcanon.com/_
