Skip to main content

Verdict

Evaluation infrastructure for AI agents.

CI Python Version License PyPI

Demo

asciicast

Install

pip install verdict-eval

Quickstart

# Run an evaluation against a built-in adapter
verdict eval --target simple_rag --num-per-category 5

# Compare two adapter versions
verdict diff --target-a simple_rag --target-b path/to/v2.py:MyAdapter --num 10

# Analyze flakiness across historical runs
verdict flakiness --target my-system --reports-dir ./reports

CLI reference

verdict eval

Run a full evaluation against a target adapter.

Flag Default Description
--target required Adapter spec: simple_rag or path/to/file.py:ClassName
--num-per-category 5 Prompts per test category
--categories all Specific categories (repeat for multiple)
--output-dir ./reports Report output directory
--run-id auto Custom run identifier
--model settings default Override LLM model for all agents
--bootstrap-iterations 1000 Bootstrap CI iterations (0 to disable)
--max-cost-usd Fail (exit 2) if total cost exceeds this amount
--max-total-latency-seconds Fail (exit 2) if total latency exceeds this
--fail-on-pass-rate-below Fail (exit 2) if pass rate < threshold
--fail-on-ci-low-below Fail (exit 2) if CI lower bound < threshold
--cache-mode off off / record / replay / update
--cache-dir .verdict_cache Directory for cached responses
--adaptive off Run adaptive follow-up probes based on initial responses

verdict diff

Compare two adapter versions against the same generated test suite.

verdict diff \
  --target-a simple_rag \
  --target-b path/to/v2.py:V2Adapter \
  --num 10

verdict flakiness

Analyze judge and target consistency across historical evaluation runs.

verdict flakiness --target my-system --min-runs 5 --reports-dir ./reports

verdict compliance

Map an eval report to HIPAA Security Rule and NIST AI RMF controls, producing machine-readable and human-readable compliance artifacts.

# After running verdict eval, point at the JSON report:
verdict compliance --report ./reports/eval_abc123.json --output-dir ./compliance

Outputs two files:

File Description
compliance_{run_id}.json Machine-readable audit artifact — control IDs, evidence entries, bootstrap CIs, token/cost provenance, eval hash
compliance_{run_id}.md Human-readable control-by-control report

Frameworks covered: 5 HIPAA Security Rule controls (general, administrative, and technical safeguards) and 8 NIST AI RMF controls (MAP, MEASURE, MANAGE functions) — a curated subset that maps naturally to eval outcomes.

What makes this statistically grounded:

  • Each control's evidence entry includes a per-source 95% bootstrap CI
  • Controls aggregated from multiple categories carry a combined CI
  • Flakiness-detected prompts reduce the confidence rating for affected controls
  • Token/cost provenance is recorded in provenance for full audit traceability

Python API:

from verdict.compliance import generate_audit_artifact, save_artifacts
from verdict.models.schemas import EvalReport
import json

report = EvalReport(**json.loads(Path("eval_report.json").read_text()))
artifact = generate_audit_artifact(report)
json_path, md_path = save_artifacts(artifact, Path("./compliance"), report.run_id)

See examples/compliance_example.py for a runnable demo with synthetic data.

Adaptive mode

When --adaptive is enabled, Verdict runs a second pass of follow-up probes selected based on each initial response. Pattern selection is entirely rule-based — no LLM is used to generate new attacks. All probes are composed from the curated OWASP LLM Top 10 pattern library in verdict/evals/attack_patterns/patterns.json.

This design ensures Verdict remains a defensive evaluation tool. See CONTRIBUTING.md for the security boundary policy.

verdict eval --target simple_rag --adaptive

Writing a custom adapter

# my_adapter.py
from verdict.adapters.base import TargetAdapter
from verdict.models.schemas import ExecutionResult, TestPrompt

class MyAdapter(TargetAdapter):
    name = "my-system"
    version = "1.0.0"

    async def execute(self, prompt: TestPrompt) -> ExecutionResult:
        response = call_my_system(prompt.prompt)
        return self.make_result(prompt, response=response)
verdict eval --target my_adapter.py:MyAdapter

Test categories

Category What it evaluates
correctness Factual accuracy and reasoning quality
safety Refusal of harmful, dangerous, or unethical requests
injection Robustness against prompt injection (OWASP LLM01, LLM07)
edge_case Graceful handling of malformed and ambiguous inputs
compliance Privacy and data handling (OWASP LLM02)

Judge calibration

The Judge is validated against 22 hand-labeled examples covering all five test categories. Results are produced by running the live judge against known ground truth — no labels were derived from judge output.

Metric Target Baseline
Pass/fail agreement (non-borderline) ≥ 80% 100% (18/18)
Critical failure detection 5 / 5 5 / 5
Score accuracy (±1) ≥ 70% 100% (10/10)

Measured on claude-sonnet-4-6, 2026-05-22.

Run calibration locally (requires ANTHROPIC_API_KEY):

pytest tests/qa/test_judge_calibration.py -v -m llm

See docs/judge_calibration.md for full methodology.

License

MIT — see LICENSE.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

verdict_eval-0.3.1.tar.gz (82.4 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

verdict_eval-0.3.1-py3-none-any.whl (106.7 kB view details)

Uploaded Python 3

File details

Details for the file verdict_eval-0.3.1.tar.gz.

File metadata

  • Download URL: verdict_eval-0.3.1.tar.gz
  • Upload date:
  • Size: 82.4 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for verdict_eval-0.3.1.tar.gz
Algorithm Hash digest
SHA256 202f9772c6089a4f32de24d118470811eee5fbfbbc8f624990fd5689a9465c77
MD5 0dc2b4e4274421538d5cad33d18f55f3
BLAKE2b-256 2d77affdff6d1c3d17ec4f2c3d9d7028d2d5ece9259888134666884f8f3de307

See more details on using hashes here.

Provenance

The following attestation bundles were made for verdict_eval-0.3.1.tar.gz:

Publisher: publish.yml on dannicolau7/verdict

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file verdict_eval-0.3.1-py3-none-any.whl.

File metadata

  • Download URL: verdict_eval-0.3.1-py3-none-any.whl
  • Upload date:
  • Size: 106.7 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for verdict_eval-0.3.1-py3-none-any.whl
Algorithm Hash digest
SHA256 6492eff168c6b43a77d2ce25612f604963e08159d80c430700a8c5f14018635e
MD5 6beb0d1156eb0547ffe305a6141789c2
BLAKE2b-256 a6a4097446ca1b3d31e87c106cf8141fece2b5cdfdb757b31702a79451dc24a6

See more details on using hashes here.

Provenance

The following attestation bundles were made for verdict_eval-0.3.1-py3-none-any.whl:

Publisher: publish.yml on dannicolau7/verdict

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page