---
title: "agentdojo vs circle-guard-bench"
type: "comparison"
canonical_url: "https://www.graphcanon.com/compare/ethz-spylab-agentdojo-vs-whitecircle-circle-guard-bench"
tools: ["ethz-spylab-agentdojo", "whitecircle-circle-guard-bench"]
---

# agentdojo vs circle-guard-bench

*GraphCanon updated Sep 20, 2026*

## Verdict

Pick agentdojo if agentDojo serves as a benchmarking environment to evaluate security attacks, like prompt injection, and defenses for Large Language Model (LLM) agents; pick circle-guard-bench if circle-guard-bench is a Python-based AI benchmark tool for evaluating large language model guard systems under various protection scenarios.

[agentdojo](https://agentdojo.spylab.ai/) reports 802 GitHub stars, 205 forks, and 51 open issues, last pushed Jun 2, 2026. [circle-guard-bench](https://whitecircle.ai) has 75 stars, 5 forks, and 1 open issues, last pushed Mar 7, 2026. Figures are from public GitHub metadata via [agentdojo's repository](https://github.com/ethz-spylab/agentdojo) and [circle-guard-bench's repository](https://github.com/whitecircle/circle-guard-bench).

| | [agentdojo](/tools/ethz-spylab-agentdojo.md) | [circle-guard-bench](/tools/whitecircle-circle-guard-bench.md) |
| --- | --- | --- |
| Tagline | A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents | AI benchmark for evaluating LLM guard systems |
| Stars | 802 | 75 |
| Forks | 205 | 5 |
| Open issues | 51 | 1 |
| Language | Python | Python |
| Adopt for | AgentDojo serves as a benchmarking environment to evaluate security attacks, like prompt injection, and defenses for Large Language Model (LLM) agents. | circle-guard-bench is a Python-based AI benchmark tool for evaluating large language model guard systems under various protection scenarios. |
| Persona | - | - |
| Runtime | - | - |
| License | MIT | Apache-2.0 |
| Categories | AI Agents, Evaluation & Observability | Evaluation & Observability |

## Trust and health

_Sourced signals - not a safety guarantee. No winner column._

| | [agentdojo](/tools/ethz-spylab-agentdojo.md) | [circle-guard-bench](/tools/whitecircle-circle-guard-bench.md) |
| --- | --- | --- |
| Days since push | 94d | 185d |
| Open issues (now) | 51 | 1 |
| Stars delta | +86 (30d) | +3 (30d) |
| Open issues delta | +10 (30d) | +1 (30d) |
| Full report | [trust report](/tools/ethz-spylab-agentdojo/trust.md) | [trust report](/tools/whitecircle-circle-guard-bench/trust.md) |

## Shared compatibility

- **Python**: [agentdojo](/tools/ethz-spylab-agentdojo.md) - Python runtime; [circle-guard-bench](/tools/whitecircle-circle-guard-bench.md) - Python runtime

## Decision facts: agentdojo

- **Pricing:** freemium - Open-source under the MIT License. Some advanced features might require additional libraries or APIs.
- **Requirements:** Min 8 GB RAM
- **Adopt for:** AgentDojo serves as a benchmarking environment to evaluate security attacks, like prompt injection, and defenses for Large Language Model (LLM) agents.

## Decision facts: circle-guard-bench

- **Adopt for:** circle-guard-bench is a Python-based AI benchmark tool for evaluating large language model guard systems under various protection scenarios.

## Choose when

### Choose agentdojo if…

- License: agentdojo is MIT, circle-guard-bench is Apache-2.0.
- Pricing: Open-source under the MIT License. Some advanced features might require additional libraries or APIs..
- Requirements: Min 8 GB RAM.
- Tags unique to agentdojo: benchmark, prompt-injection, security.
- Also covers AI Agents.
- AgentDojo serves as a benchmarking environment to evaluate security attacks, like prompt injection, and defenses for Large Language Model (LLM) agents.

### Choose circle-guard-bench if…

- License: circle-guard-bench is Apache-2.0, agentdojo is MIT.
- Tags unique to circle-guard-bench: ai, benchmarking, guardrail, llm-evaluation.
- Use circle-guard-bench when you need to evaluate the effectiveness of guardrails and safeguards in your LLM environment, as it offers an unparalleled set of scenarios specific to these protections.

## When NOT to use agentdojo

- Last GitHub push was Jun 2, 2026 (slowing maintenance). Validate activity before betting a new project on agentdojo.
- AI Agents: Don't use an agent loop when a deterministic workflow would do; agents add latency, cost, and non-determinism.
- Evaluation & Observability: Defer heavyweight eval infra only until you have real traffic - never skip it once users depend on answers.

## When NOT to use circle-guard-bench

- Avoid circle-guard-bench if your primary focus is on benchmarking the performance aspects like speed and latency of LLMs, as it specializes in evaluating protections rather than performance.
- Do not use this tool when you intend to conduct general purpose evaluations or comparisons between different LLM models that do not specifically involve security-related guard systems.

## Common questions

### What is the difference between agentdojo and circle-guard-bench?

agentdojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents. circle-guard-bench: AI benchmark for evaluating LLM guard systems. See the comparison table for live GitHub stats and shared categories.

### When should I choose agentdojo over circle-guard-bench?

Choose agentdojo over circle-guard-bench when License: agentdojo is MIT, circle-guard-bench is Apache-2.0; Pricing: Open-source under the MIT License. Some advanced features might require additional libraries or APIs.; Requirements: Min 8 GB RAM; Tags unique to agentdojo: benchmark, prompt-injection, security; Also covers AI Agents; AgentDojo serves as a benchmarking environment to evaluate security attacks, like prompt injection, and defenses for Large Language Model (LLM) agents.

### When should I choose circle-guard-bench over agentdojo?

Choose circle-guard-bench over agentdojo when License: circle-guard-bench is Apache-2.0, agentdojo is MIT; Tags unique to circle-guard-bench: ai, benchmarking, guardrail, llm-evaluation; Use circle-guard-bench when you need to evaluate the effectiveness of guardrails and safeguards in your LLM environment, as it offers an unparalleled set of scenarios specific to these protections.

### When should I avoid agentdojo?

Last GitHub push was Jun 2, 2026 (slowing maintenance). Validate activity before betting a new project on agentdojo. AI Agents: Don't use an agent loop when a deterministic workflow would do; agents add latency, cost, and non-determinism. Evaluation & Observability: Defer heavyweight eval infra only until you have real traffic - never skip it once users depend on answers.

### When should I avoid circle-guard-bench?

Avoid circle-guard-bench if your primary focus is on benchmarking the performance aspects like speed and latency of LLMs, as it specializes in evaluating protections rather than performance. Do not use this tool when you intend to conduct general purpose evaluations or comparisons between different LLM models that do not specifically involve security-related guard systems.

### Is agentdojo or circle-guard-bench more popular on GitHub?

agentdojo has more GitHub stars (802 vs 75). Stars measure visibility, not whether either tool fits your constraints.

### Are agentdojo and circle-guard-bench open source?

Yes - both are open-source projects on GitHub (agentdojo: MIT, circle-guard-bench: Apache-2.0).

### Where can I find alternatives to agentdojo or circle-guard-bench?

GraphCanon lists graph-backed alternatives at [agentdojo alternatives](/tools/ethz-spylab-agentdojo/alternatives) and [circle-guard-bench alternatives](/tools/whitecircle-circle-guard-bench/alternatives) ([agentdojo markdown twin](/tools/ethz-spylab-agentdojo/alternatives.md), [circle-guard-bench markdown twin](/tools/whitecircle-circle-guard-bench/alternatives.md)), ranked by typed relationship edges rather than popularity votes.

### Is there a machine-readable version of this comparison?

Yes. The markdown twin at [this comparison](/compare/ethz-spylab-agentdojo-vs-whitecircle-circle-guard-bench.md) mirrors this page for agents and LLM crawlers, with the same stats table and FAQ answers.

### Which is better maintained, agentdojo or circle-guard-bench?

agentdojo: Slowing. circle-guard-bench: Slowing. Compare maintenance labels, days since push, and release cadence in the trust section below - stars alone do not measure maintenance.

### Where are the full trust reports for agentdojo and circle-guard-bench?

GraphCanon publishes per-repo trust reports with dated maintenance, provenance, and scan summaries: [agentdojo trust report](/tools/ethz-spylab-agentdojo/trust); [circle-guard-bench trust report](/tools/whitecircle-circle-guard-bench/trust).

---

**Machine-readable endpoints**

- JSON: [`/api/graphcanon/graph?tool=ethz-spylab-agentdojo`](/api/graphcanon/graph?tool=ethz-spylab-agentdojo)
- LLM index: [/llms.txt](/llms.txt)
- Full corpus: [/llms-full.txt](/llms-full.txt)

_GraphCanon - The knowledge graph for AI development. https://www.graphcanon.com/_
