ActionRank

Test LLM outputs

Actively maintained

promptfoo/promptfoo-action · MIT

The GitHub Action for Promptfoo. Test your prompts, agents, and RAGs. AI Red teaming, pentesting, and vulnerability scanning for LLMs. Compare performance of GPT, Claude, Gemini, Llama, and more. Simple declarative configs with command line and CI/CD integration.

69 starsLast commit 17 days agoLatest v1.3
B
74
/ 100
Security 75Maintenance 100Popularity 40Reliability 64

Security signals

OpenSSF ScorecardNo data
SECURITY.md presentYes
Immutable releasesNot enabled
Known vulnerabilitiesNone on record

How to use it safely

Recommended: pin to commit SHA
uses: promptfoo/promptfoo-action@04839e664f52212b877170219dab0d7ad2bf6440 # v1.3

Mutable tags like v1.3 can be rewritten to point at malicious commits. Pinning to the full commit SHA is the only reference GitHub guarantees immutable.

Full workflow example
steps:
  - uses: promptfoo/promptfoo-action@04839e664f52212b877170219dab0d7ad2bf6440 # v1.3

Score breakdown

Security (35%)75
Popularity (20%)40
Maintenance (30%)100
Reliability (15%)64