
GitHub Action scanner for LLM-specific app vulnerabilities like prompt injection.
GitHub Action scanner for LLM-specific app vulnerabilities like prompt injection.
Promptfoo Code Scanning is a GitHub Action-based security scanner designed to detect vulnerabilities specific to applications built on large language models (LLMs) and AI agents. It integrates into the pull request (PR) review workflow and performs agentic code tracing to identify security issues before they reach production. The scanner focuses on LLM-specific vulnerability classes, including: - Prompt Injection: untrusted input reaching LLM prompts without sanitization - Data Exfiltration: indirect prompt injection vectors that could extract data through agent tools - PII Exposure: code that may leak sensitive user data to LLMs or log confidential information - Improper Output Handling: LLM outputs used in dangerous contexts such as SQL queries or shell commands - Excessive Agency: LLMs with overly broad tool access or missing approval gates - Jailbreak Risks: weak system prompts or guardrail bypasses that could allow harmful outputs Key operational characteristics: - Deep tracing: the scanner goes beyond the PR diff, tracing LLM inputs, outputs, and capability changes throughout the broader repository - Low false-positive design: maintains a high reporting bar to reduce alert fatigue; maintainers can configure severity levels and provide custom instructions - Fix suggestions: each finding includes a suggested remediation and a prompt that can be passed to an AI coding agent for further investigation and resolution The tool has been tested against real CVEs in LangChain, Vanna.AI, and LlamaIndex. No account, credit card, or API keys are required to get started.
Common questions about Promptfoo Code Scanning / GitHub Action including features, pricing, alternatives, and user reviews.
Promptfoo Code Scanning / GitHub Action is GitHub Action scanner for LLM-specific app vulnerabilities like prompt injection, developed by Promptfoo. It is a AI Security solution designed to help security teams with LLM Security, Prompt Injection, GenAI Security.
Promptfoo Code Scanning / GitHub Action offers the following core capabilities:
Promptfoo Code Scanning / GitHub Action integrates natively with GitHub, GitHub Actions. Integration support lets security teams connect Promptfoo Code Scanning / GitHub Action to existing SIEM, ticketing, identity, and notification systems without custom development.
Promptfoo Code Scanning / GitHub Action is built for security teams handling LLM Security, Prompt Injection, GenAI Security, Agentic AI Security. It supports workflows including detection of prompt injection vulnerabilities in llm applications, identification of data exfiltration vectors via indirect prompt injection, pii exposure detection in llm inputs and logs. Teams typically adopt Promptfoo Code Scanning / GitHub Action when they need to ai security capabilities integrated into their existing stack. Explore similar tools at https://cybersectools.com/alternatives/promptfoo-code-scanning-github-action
Promptfoo Code Scanning / GitHub Action is a free AI Security tool. This makes it accessible for organizations of all sizes, from startups to enterprises. Visit https://www.promptfoo.dev/code-scanning/github-action/ for download and installation instructions.
Popular alternatives to Promptfoo Code Scanning / GitHub Action include:
Compare all Promptfoo Code Scanning / GitHub Action alternatives at https://cybersectools.com/alternatives/promptfoo-code-scanning-github-action
Promptfoo Code Scanning / GitHub Action is for security teams and organizations that need LLM Security, Prompt Injection, GenAI Security, Agentic AI Security, DEVSECOPS. It's particularly suitable for small to medium-sized teams looking for cost-effective solutions. Other AI Security tools can be found at https://cybersectools.com/categories/ai-security
Head-to-head feature, pricing, and rating breakdowns.
GenAI security platform for shadow AI discovery, prompt injection defense & DLP