Back to browse949687
DSPy
FrameworkThe framework for programming — not prompting — language models
Stanford NLP267.0K installs4.5 (1.8K)
81
TrustedSecurity
69
Quality
90
Maintenance
89
Safety Tier Low Risk
Security ScanWarnings
PriceFree
Last Scanned5/12/2026
About
Declarative framework from Stanford NLP that compiles high-level definitions into optimized prompts and fine-tuned weights. Uses typed signatures rather than handcrafted prompts. 34k+ GitHub stars.
Tags
Categories
AI InfrastructureFrameworks
Security Scan
69/100
12 checks · 9 passed · 3 findings5/13/2026
Scanners:customsemgrepgitleakstrivy
SSRF Detection1
Prompt Injection1
Data Exfiltration
Dangerous Commands
Secret Detection
Obfuscation
External Fetches
Credential Access
Privilege Escalation
Secret Detection (Gitleaks)
Static Security Analysis
Dependency Vulnerabilities1
Findings (3)
highUnvalidated URL fetchingcustom
dspy/clients/databricks.py:128
highRole hijackingcustom
pyproject.toml:20
highIn versions 3.0.0a1 through 3.2.0 of Mistune, there is a ReDoS (Regula ...trivy
docs/requirements.txt:0
50 files scanned from repository
Related Frameworks
CrewAI
Multi-agent orchestration framework
FrameworkFreeScanned
234.5K4.4(1.6K)CrewAI
PythonAny LLM
LangGraph
Stateful multi-actor agent framework
FrameworkFreeScanned
198.7K4.5(1.2K)LangChain
PythonJavaScriptAny LLM
OpenAI Swarm
Lightweight multi-agent orchestration
FrameworkFreeScanned
98.4K4.2(567)OpenAI
PythonOpenAI