Comparison
agentdojo vs jailbreakbench
Verdict
Pick agentdojo if agentDojo serves as a benchmarking environment to evaluate security attacks, like prompt injection, and defenses for Large Language Model (LLM) agents; pick jailbreakbench if jailbreakBench is an open robustness benchmark specifically designed to evaluate language models against jailbreaking attacks. It aims to quantify the resilience of language models under adversarial conditions.
Markdown twin · agentdojo alternatives · jailbreakbench alternatives
GraphCanon updated 2w
Trust & integrity
| Signal | agentdojo | jailbreakbench |
|---|---|---|
| Maintenance | Steady (63d since push) As of 2w · github_public_v1 | Dormant (487d since push) As of 2w · github_public_v1 |
| Provenance | Not a fork · Organization account As of 2w · github_public_v1 | Not a fork · Organization account As of 2w · github_public_v1 |
| OSV dependency advisories | No lockfile (source not queried) As of 1mo · osv@v1 | No lockfile (source not queried) As of 1mo · osv@v1 |
| deps.dev advisories | Not queried deps.dev@v1 | Not queried deps.dev@v1 |
| OpenSSF Scorecard | Not queried openssf-scorecard@v1 | Not queried openssf-scorecard@v1 |
Tagline
- agentdojo
- A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
- jailbreakbench
- An Open Robustness Benchmark for Jailbreaking Language Models
Stars
- agentdojo
- 716
- jailbreakbench
- 645
Forks
- agentdojo
- 188
- jailbreakbench
- 75
Open issues
- agentdojo
- 41
- jailbreakbench
- 11
Language
- agentdojo
- Python
- jailbreakbench
- Python
Adopt for
- agentdojo
- AgentDojo serves as a benchmarking environment to evaluate security attacks, like prompt injection, and defenses for Large Language Model (LLM) agents.
- jailbreakbench
- JailbreakBench is an open robustness benchmark specifically designed to evaluate language models against jailbreaking attacks. It aims to quantify the resilience of language models under adversarial conditions.
Persona
- agentdojo
- -
- jailbreakbench
- -
Runtime
- agentdojo
- -
- jailbreakbench
- -
License
- agentdojo
- MIT
- jailbreakbench
- MIT
Last pushed
- agentdojo
- Jun 2, 2026
- jailbreakbench
- Apr 4, 2025
Categories
- agentdojo
- AI Agents, Evaluation & Observability
- jailbreakbench
- Evaluation & Observability
Trust and health
Maintenance
- agentdojo
- Steady (60%)
- jailbreakbench
- Dormant (18%)
Days since push
- agentdojo
- 63d
- jailbreakbench
- 487d
Open issues (now)
- agentdojo
- 41
- jailbreakbench
- 11
Full report
- agentdojo
- Trust report
- jailbreakbench
- Trust report
Shared compatibility
- Python · agentdojo: Python runtime · jailbreakbench: Python runtime
Choose agentdojo if…
- Pricing: Open-source under the MIT License. Some advanced features might require additional libraries or APIs..
- Requirements: Min 8 GB RAM.
- Tags unique to agentdojo: benchmark, large language models, prompt-injection, security.
- Also covers AI Agents.
- AgentDojo serves as a benchmarking environment to evaluate security attacks, like prompt injection, and defenses for Large Language Model (LLM) agents.
When NOT to use agentdojo
- AI Agents: Don't use an agent loop when a deterministic workflow would do; agents add latency, cost, and non-determinism.
- Evaluation & Observability: Defer heavyweight eval infra only until you have real traffic - never skip it once users depend on answers.
Choose jailbreakbench if…
- Tags unique to jailbreakbench: jailbreaking, language-models, neurips-2024-datasets-and-benchmarks-tra, robustness-benchmark.
- JailbreakBench is an open robustness benchmark specifically designed to evaluate language models against jailbreaking attacks. It aims to quantify the resilience of language models under adversarial conditions.
- Leaner open-issue backlog (11).
When NOT to use jailbreakbench
- Last GitHub push was 508 days ago (dormant maintenance, Apr 4, 2025). Validate activity before betting a new project on jailbreakbench.
- Evaluation & Observability: Defer heavyweight eval infra only until you have real traffic - never skip it once users depend on answers.
Explore
Sources
Every stat on this page traces to a dated GitHub sync, license file, enrichment field, or trust scan.
- GitHub stars (ethz-spylab/agentdojo) · observed Aug 5, 2026
- GitHub forks (ethz-spylab/agentdojo) · observed Aug 5, 2026
- Last push (ethz-spylab/agentdojo) · observed Jun 2, 2026
- License file (MIT) · observed Aug 5, 2026
- Decision facts (enrichment) · observed Jul 12, 2026
- Trust scan (lockfile / OSV) · observed Jul 11, 2026
- GitHub stars (JailbreakBench/jailbreakbench) · observed Aug 5, 2026
- GitHub forks (JailbreakBench/jailbreakbench) · observed Aug 5, 2026
- Last push (JailbreakBench/jailbreakbench) · observed Apr 4, 2025
- License file (MIT) · observed Aug 5, 2026
- Decision facts (enrichment) · observed Jul 12, 2026
- Trust scan (lockfile / OSV) · observed Jul 11, 2026
GitHub stars on cards: agentdojo 716 · jailbreakbench 645 (synced Aug 5, 2026).
Common questions
- What is the difference between agentdojo and jailbreakbench?
- agentdojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents. jailbreakbench: An Open Robustness Benchmark for Jailbreaking Language Models. See the comparison table for live GitHub stats and shared categories.
- When should I choose agentdojo over jailbreakbench?
- Choose agentdojo over jailbreakbench when Pricing: Open-source under the MIT License. Some advanced features might require additional libraries or APIs.; Requirements: Min 8 GB RAM; Tags unique to agentdojo: benchmark, large language models, prompt-injection, security; Also covers AI Agents; AgentDojo serves as a benchmarking environment to evaluate security attacks, like prompt injection, and defenses for Large Language Model (LLM) agents.
- When should I choose jailbreakbench over agentdojo?
- Choose jailbreakbench over agentdojo when Tags unique to jailbreakbench: jailbreaking, language-models, neurips-2024-datasets-and-benchmarks-tra, robustness-benchmark; JailbreakBench is an open robustness benchmark specifically designed to evaluate language models against jailbreaking attacks. It aims to quantify the resilience of language models under adversarial conditions; Leaner open-issue backlog (11).
- When should I avoid agentdojo?
- AI Agents: Don't use an agent loop when a deterministic workflow would do; agents add latency, cost, and non-determinism. Evaluation & Observability: Defer heavyweight eval infra only until you have real traffic - never skip it once users depend on answers.
- When should I avoid jailbreakbench?
- Last GitHub push was 508 days ago (dormant maintenance, Apr 4, 2025). Validate activity before betting a new project on jailbreakbench. Evaluation & Observability: Defer heavyweight eval infra only until you have real traffic - never skip it once users depend on answers.
- Is agentdojo or jailbreakbench more popular on GitHub?
- agentdojo has more GitHub stars (716 vs 645). Stars measure visibility, not whether either tool fits your constraints.
- Are agentdojo and jailbreakbench open source?
- Yes - both are open-source projects on GitHub (agentdojo: MIT, jailbreakbench: MIT).
- Where can I find alternatives to agentdojo or jailbreakbench?
- GraphCanon lists graph-backed alternatives at agentdojo alternatives and jailbreakbench alternatives (agentdojo markdown twin, jailbreakbench markdown twin), ranked by typed relationship edges rather than popularity votes.
- Is there a machine-readable version of this comparison?
- Yes. The markdown twin at this comparison mirrors this page for agents and LLM crawlers, with the same stats table and FAQ answers.
- Which is better maintained, agentdojo or jailbreakbench?
- agentdojo: Steady. jailbreakbench: Dormant. Compare maintenance labels, days since push, and release cadence in the trust section below - stars alone do not measure maintenance.
- Where are the full trust reports for agentdojo and jailbreakbench?
- GraphCanon publishes per-repo trust reports with dated maintenance, provenance, and scan summaries: agentdojo trust report; jailbreakbench trust report.