RAMPART
APIyesOSS—FREE—DOCS5/5
RA6.9#14 of 29
—WeboutWindowsoutMacoutLinux—Android—iOS
Ranked in AI Security Testing Tools ·No free plan on record
About
RAMPART is ranked #14 of 29 in AI security testing tools on Inferse. It runs on API, Linux, macOS, Windows.
Compared on AI security testing tools
- Prompt injection tests
- Yesmicrosoft.github.io
- Data leakage tests
- Yesmicrosoft.github.io
- Unsafe output tests
- Yesmicrosoft.github.io
- Custom test cases
- Yesmicrosoft.github.io
- Deployment mode
- self_hostedmicrosoft.github.io
Facts
- Purpose
- RAMPART is a pytest-native safety testing framework for agentic AI applications that orchestrates attacks or probes, evaluates outcomes, and reports results.microsoft.github.io · 8 Oct 2026
- Attack and probe tests
- Its two test categories are attacks, where a detected attack means UNSAFE, and probes, where detected expected behavior means SAFE.microsoft.github.io · 8 Oct 2026
- Included tests
- The documented built-in attack is cross-prompt injection (XPIA), and the documented probe verifies expected agent behavior.microsoft.github.io · 8 Oct 2026
- Integration model
- Users provide an adapter connecting their agent to RAMPART, which supplies execution strategies, evaluators, pytest integration, and reporting.microsoft.github.io · 8 Oct 2026
- PyRIT
- RAMPART uses PyRIT for LLM interaction, prompt normalization, and conversation memory, and installs PyRIT as a dependency.microsoft.github.io · 8 Oct 2026
- OneDrive
- An optional onedrive extra installs dependencies for using the built-in OneDriveSurface to place XPIA payloads in OneDrive.microsoft.github.io · 8 Oct 2026
- Python requirement
- Installation requires Python 3.11 or later and uses uv or pip for package management.microsoft.github.io · 8 Oct 2026
- Supported installation systems
- The installation instructions provide commands for Linux, macOS, and Windows.microsoft.github.io · 8 Oct 2026
- pytest plugin
- RAMPART registers automatically as a pytest plugin through the pytest11 entry point, without requiring conftest.py activation configuration.microsoft.github.io · 8 Oct 2026
- Reporting
- RAMPART provides structured JSON reporting, including a built-in JSON file report sink and a hook for custom sinks.microsoft.github.io · 8 Oct 2026
- Parallel execution
- RAMPART supports pytest-xdist parallel runs and produces a unified report across worker processes.microsoft.github.io · 8 Oct 2026
- Security boundary
- For xdist worker serialization, RAMPART documents JSON-safe payloads, rejection of unknown schema versions, a default 16 MiB per-result cap, and ANSI escape stripping.microsoft.github.io · 8 Oct 2026
- Limitations
- The xdist documentation says results recorded only during fixture teardown are excluded from report streaming and mixed RAMPART versions across controller and workers are unsupported.microsoft.github.io · 8 Oct 2026
- Maker
- The documentation identifies Microsoft Corporation as its copyright holder.microsoft.github.io · 8 Oct 2026
- Test workflow
- It orchestrates agent interactions, evaluates outcomes, and reports test results.microsoft.github.io · 9 Oct 2026
- Attack testing
- Its XPIA tests check whether malicious content planted in data sources can manipulate an agent when retrieved.microsoft.github.io · 9 Oct 2026
- Behavior probes
- Behavioral probes check for expected responses, tool use, or side effects and are described as useful for regression testing.microsoft.github.io · 9 Oct 2026
- Evaluation output
- Results include a safety status of SAFE, UNSAFE, UNDETERMINED, or ERROR, along with trace and evaluation details.microsoft.github.io · 9 Oct 2026
- pytest integration
- RAMPART registers as a pytest plugin automatically and provides harm and trial markers.microsoft.github.io · 9 Oct 2026
- Reporting and CI
- Built-in JSON report sinks and pytest-xdist support let teams collect reports for CI dashboards across parallel workers.microsoft.github.io · 9 Oct 2026
- PyRIT integration
- RAMPART uses PyRIT for LLM interaction, prompt normalization, and conversation memory, and installs PyRIT as a dependency.microsoft.github.io · 9 Oct 2026
- Install requirements
- The installation guide requires Python 3.11 or later and supports installation with uv or pip.microsoft.github.io · 9 Oct 2026
- Optional integration
- The optional onedrive extra adds dependencies for using the built-in OneDriveSurface to place XPIA payloads in OneDrive.microsoft.github.io · 9 Oct 2026
- License
- The GitHub repository identifies RAMPART as MIT-licensed.github.com · 9 Oct 2026
- Intended users
- The project describes its framework as a developer-friendly way to write and run safety and security tests for AI agents.github.com · 9 Oct 2026
Best RAMPART alternatives
See all 20Where it ranks on Inferse
Sources
- microsoft.github.io/RAMPART/· checked 8 Oct 2026
- microsoft.github.io/RAMPART/concepts/overview/· checked 8 Oct 2026
- microsoft.github.io/RAMPART/concepts/pyrit/· checked 8 Oct 2026
- microsoft.github.io/RAMPART/getting-started/installation/· checked 8 Oct 2026
- microsoft.github.io/RAMPART/usage/xdist/· checked 8 Oct 2026
- microsoft.github.io/RAMPART/attacks/xpia/· checked 9 Oct 2026
- microsoft.github.io/RAMPART/probes/behavioral/· checked 9 Oct 2026
- microsoft.github.io/RAMPART/usage/results-and-reporting/· checked 9 Oct 2026
- microsoft.github.io/RAMPART/usage/ci-integration/· checked 9 Oct 2026
- github.com/microsoft/RAMPART· checked 9 Oct 2026


