Skip to main content

Verdict

Evaluation infrastructure for AI agents.

CI Python Version License PyPI

Demo

asciicast

Install

pip install verdict-eval

Quickstart

# Run an evaluation against a built-in adapter
verdict eval --target simple_rag --num-per-category 5

# Compare two adapter versions
verdict diff --target-a simple_rag --target-b path/to/v2.py:MyAdapter --num 10

# Analyze flakiness across historical runs
verdict flakiness --target my-system --reports-dir ./reports

CLI reference

verdict eval

Run a full evaluation against a target adapter.

Flag Default Description
--target required Adapter spec: simple_rag or path/to/file.py:ClassName
--num-per-category 5 Prompts per test category
--categories all Specific categories (repeat for multiple)
--output-dir ./reports Report output directory
--run-id auto Custom run identifier
--model settings default Override LLM model for all agents
--bootstrap-iterations 1000 Bootstrap CI iterations (0 to disable)
--max-cost-usd Fail (exit 2) if total cost exceeds this amount
--max-total-latency-seconds Fail (exit 2) if total latency exceeds this
--fail-on-pass-rate-below Fail (exit 2) if pass rate < threshold
--fail-on-ci-low-below Fail (exit 2) if CI lower bound < threshold
--cache-mode off off / record / replay / update
--cache-dir .verdict_cache Directory for cached responses
--adaptive off Run adaptive follow-up probes based on initial responses

verdict diff

Compare two adapter versions against the same generated test suite.

verdict diff \
  --target-a simple_rag \
  --target-b path/to/v2.py:V2Adapter \
  --num 10

verdict flakiness

Analyze judge and target consistency across historical evaluation runs.

verdict flakiness --target my-system --min-runs 5 --reports-dir ./reports

verdict compliance

Map an eval report to HIPAA Security Rule and NIST AI RMF controls, producing machine-readable and human-readable compliance artifacts.

# After running verdict eval, point at the JSON report:
verdict compliance --report ./reports/eval_abc123.json --output-dir ./compliance

Outputs two files:

File Description
compliance_{run_id}.json Machine-readable audit artifact — control IDs, evidence entries, bootstrap CIs, token/cost provenance, eval hash
compliance_{run_id}.md Human-readable control-by-control report

Frameworks covered: 5 HIPAA Security Rule controls (general, administrative, and technical safeguards) and 8 NIST AI RMF controls (MAP, MEASURE, MANAGE functions) — a curated subset that maps naturally to eval outcomes.

What makes this statistically grounded:

  • Each control's evidence entry includes a per-source 95% bootstrap CI
  • Controls aggregated from multiple categories carry a combined CI
  • Flakiness-detected prompts reduce the confidence rating for affected controls
  • Token/cost provenance is recorded in provenance for full audit traceability

Python API:

from verdict.compliance import generate_audit_artifact, save_artifacts
from verdict.models.schemas import EvalReport
import json

report = EvalReport(**json.loads(Path("eval_report.json").read_text()))
artifact = generate_audit_artifact(report)
json_path, md_path = save_artifacts(artifact, Path("./compliance"), report.run_id)

See examples/compliance_example.py for a runnable demo with synthetic data.

Adaptive mode

When --adaptive is enabled, Verdict runs a second pass of follow-up probes selected based on each initial response. Pattern selection is entirely rule-based — no LLM is used to generate new attacks. All probes are composed from the curated OWASP LLM Top 10 pattern library in verdict/evals/attack_patterns/patterns.json.

This design ensures Verdict remains a defensive evaluation tool. See CONTRIBUTING.md for the security boundary policy.

verdict eval --target simple_rag --adaptive

Writing a custom adapter

# my_adapter.py
from verdict.adapters.base import TargetAdapter
from verdict.models.schemas import ExecutionResult, TestPrompt

class MyAdapter(TargetAdapter):
    name = "my-system"
    version = "1.0.0"

    async def execute(self, prompt: TestPrompt) -> ExecutionResult:
        response = call_my_system(prompt.prompt)
        return self.make_result(prompt, response=response)
verdict eval --target my_adapter.py:MyAdapter

Test categories

Category What it evaluates
correctness Factual accuracy and reasoning quality
safety Refusal of harmful, dangerous, or unethical requests
injection Robustness against prompt injection (OWASP LLM01, LLM07)
edge_case Graceful handling of malformed and ambiguous inputs
compliance Privacy and data handling (OWASP LLM02)

Judge calibration

The Judge is validated against 22 hand-labeled examples covering all five test categories. Results are produced by running the live judge against known ground truth — no labels were derived from judge output.

Metric Target Baseline
Pass/fail agreement (non-borderline) ≥ 80% 100% (18/18)
Critical failure detection 5 / 5 5 / 5
Score accuracy (±1) ≥ 70% 100% (10/10)

Measured on claude-sonnet-4-6, 2026-05-22.

Run calibration locally (requires ANTHROPIC_API_KEY):

pytest tests/qa/test_judge_calibration.py -v -m llm

See docs/judge_calibration.md for full methodology.

License

MIT — see LICENSE.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

verdict_eval-0.2.0.tar.gz (72.0 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

verdict_eval-0.2.0-py3-none-any.whl (91.9 kB view details)

Uploaded Python 3

File details

Details for the file verdict_eval-0.2.0.tar.gz.

File metadata

  • Download URL: verdict_eval-0.2.0.tar.gz
  • Upload date:
  • Size: 72.0 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for verdict_eval-0.2.0.tar.gz
Algorithm Hash digest
SHA256 ff3dab2725e3978f1427505428e63da8177aad9c465436ac161eea17fc17000e
MD5 26b11636de02eec022cf60b11a316ab0
BLAKE2b-256 92d18da339115b7e6f550daee20f1e584283d7b8fbade2f7ffdb08f84d771247

See more details on using hashes here.

Provenance

The following attestation bundles were made for verdict_eval-0.2.0.tar.gz:

Publisher: publish.yml on dannicolau7/verdict

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file verdict_eval-0.2.0-py3-none-any.whl.

File metadata

  • Download URL: verdict_eval-0.2.0-py3-none-any.whl
  • Upload date:
  • Size: 91.9 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for verdict_eval-0.2.0-py3-none-any.whl
Algorithm Hash digest
SHA256 5604395a8b0af37764dc40d9513218ec8b130a228021e231ad6dea22a78cf2cf
MD5 018cc4f6119356b5b9086dc40335397e
BLAKE2b-256 b094f5dab4a7ccfee204d8436fe807cd356492cca3e38c77ed85da608a4f5aba

See more details on using hashes here.

Provenance

The following attestation bundles were made for verdict_eval-0.2.0-py3-none-any.whl:

Publisher: publish.yml on dannicolau7/verdict

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page