RAMPART

APIyesOSS—FREE—DOCS5/5
RA6.9#14 of 29
—WeboutWindowsoutMacoutLinux—Android—iOS

Ranked in AI Security Testing Tools ·No free plan on record

About

RAMPART is ranked #14 of 29 in AI security testing tools on Inferse. It runs on API, Linux, macOS, Windows.

Compared on AI security testing tools

Prompt injection tests
Yesmicrosoft.github.io
Data leakage tests
Yesmicrosoft.github.io
Unsafe output tests
Yesmicrosoft.github.io
Custom test cases
Yesmicrosoft.github.io
Deployment mode
self_hostedmicrosoft.github.io

Facts

Purpose
RAMPART is a pytest-native safety testing framework for agentic AI applications that orchestrates attacks or probes, evaluates outcomes, and reports results.microsoft.github.io · 8 Oct 2026
Attack and probe tests
Its two test categories are attacks, where a detected attack means UNSAFE, and probes, where detected expected behavior means SAFE.microsoft.github.io · 8 Oct 2026
Included tests
The documented built-in attack is cross-prompt injection (XPIA), and the documented probe verifies expected agent behavior.microsoft.github.io · 8 Oct 2026
Integration model
Users provide an adapter connecting their agent to RAMPART, which supplies execution strategies, evaluators, pytest integration, and reporting.microsoft.github.io · 8 Oct 2026
PyRIT
RAMPART uses PyRIT for LLM interaction, prompt normalization, and conversation memory, and installs PyRIT as a dependency.microsoft.github.io · 8 Oct 2026
OneDrive
An optional onedrive extra installs dependencies for using the built-in OneDriveSurface to place XPIA payloads in OneDrive.microsoft.github.io · 8 Oct 2026
Python requirement
Installation requires Python 3.11 or later and uses uv or pip for package management.microsoft.github.io · 8 Oct 2026
Supported installation systems
The installation instructions provide commands for Linux, macOS, and Windows.microsoft.github.io · 8 Oct 2026
pytest plugin
RAMPART registers automatically as a pytest plugin through the pytest11 entry point, without requiring conftest.py activation configuration.microsoft.github.io · 8 Oct 2026
Reporting
RAMPART provides structured JSON reporting, including a built-in JSON file report sink and a hook for custom sinks.microsoft.github.io · 8 Oct 2026
Parallel execution
RAMPART supports pytest-xdist parallel runs and produces a unified report across worker processes.microsoft.github.io · 8 Oct 2026
Security boundary
For xdist worker serialization, RAMPART documents JSON-safe payloads, rejection of unknown schema versions, a default 16 MiB per-result cap, and ANSI escape stripping.microsoft.github.io · 8 Oct 2026
Limitations
The xdist documentation says results recorded only during fixture teardown are excluded from report streaming and mixed RAMPART versions across controller and workers are unsupported.microsoft.github.io · 8 Oct 2026
Maker
The documentation identifies Microsoft Corporation as its copyright holder.microsoft.github.io · 8 Oct 2026
Test workflow
It orchestrates agent interactions, evaluates outcomes, and reports test results.microsoft.github.io · 9 Oct 2026
Attack testing
Its XPIA tests check whether malicious content planted in data sources can manipulate an agent when retrieved.microsoft.github.io · 9 Oct 2026
Behavior probes
Behavioral probes check for expected responses, tool use, or side effects and are described as useful for regression testing.microsoft.github.io · 9 Oct 2026
Evaluation output
Results include a safety status of SAFE, UNSAFE, UNDETERMINED, or ERROR, along with trace and evaluation details.microsoft.github.io · 9 Oct 2026
pytest integration
RAMPART registers as a pytest plugin automatically and provides harm and trial markers.microsoft.github.io · 9 Oct 2026
Reporting and CI
Built-in JSON report sinks and pytest-xdist support let teams collect reports for CI dashboards across parallel workers.microsoft.github.io · 9 Oct 2026
PyRIT integration
RAMPART uses PyRIT for LLM interaction, prompt normalization, and conversation memory, and installs PyRIT as a dependency.microsoft.github.io · 9 Oct 2026
Install requirements
The installation guide requires Python 3.11 or later and supports installation with uv or pip.microsoft.github.io · 9 Oct 2026
Optional integration
The optional onedrive extra adds dependencies for using the built-in OneDriveSurface to place XPIA payloads in OneDrive.microsoft.github.io · 9 Oct 2026
License
The GitHub repository identifies RAMPART as MIT-licensed.github.com · 9 Oct 2026
Intended users
The project describes its framework as a developer-friendly way to write and run safety and security tests for AI agents.github.com · 9 Oct 2026

Best RAMPART alternatives

See all 20