Vijil DART tests AI agents for security flaws and policy violations
Vijil has released Diamond Adaptive Red Teaming for Agents (DART), an automated testing system that finds security vulnerabilities and policy violations in enterprise AI agents. DART employs multiple adversarial agents of its own to probe the target’s defenses with multi-turn attacks that learn and adapt tactics across turns, episodes, and engagements. Using DART, AI developers and application security engineers can find more issues across their agent fleet than with red-team tools and services that use static test prompts.
Gartner estimates that an average global Fortune 500 company will be using more than 150,000 agents by 2028, compared to fewer than 15 in 2025. AI engineering and AI governance teams don’t have the bandwidth or the budget to test all these agents by hand. Meanwhile, threat actors are increasingly deploying their own agents to launch sustained, multi-turn attacks against enterprise AI systems.
Existing red-teaming tools try to match the pattern of known attacks but fail to keep up, let alone develop new strategies and tactics to evade the target agent’s defenses. Most do little more than check an agent’s output against a static set of attack prompts. They test the language model and the chat interface. And they run under supervision by external consultants, outside the agent development lifecycle, often only days before deployment, making it hard for developers to address critical and important findings in time for launch.
DART is different. It enables AI teams to test the whole agent — its tool-use, memory, and multi-turn behavior — using attacks that adapt to the target agent in its own environment, rather than relying on a fixed script. It combines scale at speed with depth in stealth to generate waves of multi-turn attacks that explore and exploit the target agent’s weaknesses. DART evaluates the agent’s response, adjusts its tactics, and retries as many times as the user specifies. It doesn’t need to be told what vulnerabilities to look for. It finds them on its own.
DART’s core capabilities include:
- Customizable risk coverage: Ships with predefined taxonomies based on OWASP, MITRE, and Vijil research, but can be derived from any enterprise-specific risk catalog.
- Adaptive attack chaining: Uses a chain of attacks across turns and episodes to explore the target’s attack surface and exploit its weaknesses.
- Developer-friendly tooling: Accessible through a plugin for coding agents including Claude Code and Codex, DART works with any agent framework or agent deployment platform to produce an auditable report that both engineering and compliance teams can use.
- Devops-ready workflow: Runs automatically at scale under sustained load, with rate limiting, retries, and per-role model configuration, deployable via APIs as part of the AI team’s CI/CD process.
- Deployment flexibility: Runs in a customer’s own VPC or fully on-prem, in air-gapped and regulated environments.
In a recent evaluation using the DecodingTrust-Agent benchmark, DART achieved an attack success rate that is 1.5X that of its closest competitor. DART surpassed the competitor’s results in nine of twelve enterprise agent tasks spanning domains including CRM, code, customer service, medical, research, and travel.
“Your custom AI agent that can access your confidential data and take consequential action on its own requires a comprehensive and customized approach to quality control,” said Vin Sharma, CEO of Vijil. “There’s a big gap between an agent that appears ready in a demo and one that proves its reliability, security, and safety under pressure. DART closes that gap, saving weeks of effort and tens of thousands of dollars compared to manual red-teaming engagements, generic benchmarks, and open source prototypes.”
DART is a new capability of Vijil Diamond, part of the Vijil platform for evolving resilience into AI agents. After DART has identified agentic weaknesses, other modules of the Vijil platform perform a root-cause analysis, implement policy-driven guardrails to defend the agent against attacks, and suggest code changes to fix the issues DART has discovered.
The Vijil platform consists of individually usable modules covering every phase of the agentic lifecycle. Vijil Discover shines a light on shadow AI by finding and fingerprinting agents wherever they are. Vijil Diamond finds flaws in agents before they go live. Vijil Dome ensures compliance with organizational policies in production. And Vijil Darwin continuously improves agents as new users, models, and attack methods emerge. Together, they ensure agents remain resilient under the most hostile conditions.