Skip to content

Quickstart

See it work (no API key)

pip install gauntlet-agent

Watch it break a deliberately fragile sample agent, in one process:

python examples/demo.py

You'll see it fire 15 probes and surface the planted bugs — a system-prompt leak (CRITICAL), an unauthorized refund (HIGH), and a 500 crash on malformed input.

Against your own agent

Point --target at any endpoint that accepts POST {"message": "..."} and returns JSON or text. Field names are configurable.

python examples/sample_agent.py     # serves :8000/chat
gauntlet run \
  --target http://localhost:8000/chat \
  --canaries examples/canaries.json \
  --fail-on HIGH \
  --json gauntlet-report.json

The exit code is nonzero when anything at or above --fail-on is found, so it drops straight into CI.

Custom field names + auth

gauntlet run \
  --target https://your-agent.example.com/v1/chat \
  --request-field input --response-field output \
  --header "Authorization: Bearer $TOKEN" \
  --canaries my_canaries.json \
  --fail-on HIGH

Network-free self-test (CI-safe)

python tests/test_offline.py    # or: pytest

Next: define canaries — the things your agent must never do.