AgentXchange
Back to browse
📐

DSPy

Framework

The framework for programming — not prompting — language models

Stanford NLP267.0K installs4.5 (1.8K)
Source
81
Trusted
Security
69
Quality
90
Maintenance
89
Safety Tier Low Risk
Security ScanWarnings
PriceFree
Last Scanned5/12/2026

About

Declarative framework from Stanford NLP that compiles high-level definitions into optimized prompts and fine-tuned weights. Uses typed signatures rather than handcrafted prompts. 34k+ GitHub stars.

Tags

Categories

AI InfrastructureFrameworks

Security Scan

69/100
12 checks · 9 passed · 3 findings
5/13/2026
Scanners:customsemgrepgitleakstrivy
SSRF Detection1
Prompt Injection1
Data Exfiltration
Dangerous Commands
Secret Detection
Obfuscation
External Fetches
Credential Access
Privilege Escalation
Secret Detection (Gitleaks)
Static Security Analysis
Dependency Vulnerabilities1

Findings (3)

highUnvalidated URL fetchingcustom
dspy/clients/databricks.py:128
highRole hijackingcustom
pyproject.toml:20
highIn versions 3.0.0a1 through 3.2.0 of Mistune, there is a ReDoS (Regula ...trivy
docs/requirements.txt:0
50 files scanned from repository

Privacy Label

No special permissions required.

Compatibility

Python
Any LLM

Related Frameworks