8 Best garak Alternatives in 2026 (Open Source)
garak — the LLM vulnerability scanner. Specialized security-focused evaluation framework that treats LLM assessment like traditional vulnerability scanning with nmap/Metasploit methodologies.
These 8 open-source tools do the same job. They are ordered by how closely they match garak, with live GitHub data so you can see which projects are actively maintained.
| Tool | GitHub stars | Stars / 30d | Last commit |
|---|---|---|---|
| garak(original) | 9.4k | +783 | 2026-09-16 |
| Promptfoo | 25.6k | +1,117 | 2026-09-30 |
| agentic-radar | 1.1k | +20 | 2025-11-27 |
| SkillSpector | 18.8k | +1,565 | 2026-09-30 |
| LLM Guard | 3.2k | +76 | 2026-07-08 |
| Guardrails | 7.2k | +218 | 2026-09-29 |
| Superagent | 6.8k | +42 | 2026-08-25 |
| langwatch | 4.9k | +277 | 2026-09-30 |
| Opik | 22.3k | +609 | 2026-09-30 |
1. Promptfoo
Test your prompts, agents, and RAGs. Red teaming/pentesting/vulnerability scanning for AI. Compare performance of GPT, Claude, Gemini, Llama, and more. Simple declarative configs with command line and
What sets it apart: Unlike LangSmith (production observability) or Langfuse (logging), promptfoo is the only open-source tool combining eval + red teaming + CI/CD code scanning — now backed by OpenAI while remaining fully MIT-licensed
Best for: Teams hardening LLM apps against prompt injection and jailbreaks with automated red teaming; Engineering teams adding LLM eval regression tests to CI/CD pipelines
2. agentic-radar
A security scanner for your LLM agentic workflows
What sets it apart: The first dedicated security scanner specifically designed for agentic AI workflows, combining static analysis with runtime adversarial testing and automatic prompt hardening — no other tool maps agent vulnerabilities to OWASP AI security frameworks
Best for: Security teams auditing agentic AI systems before production deployment; DevOps teams integrating AI security scanning into CI/CD pipelines
3. SkillSpector
Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and supply-chain risks in
What sets it apart: Specialized security scanner focused exclusively on AI agent skills with 71 vulnerability patterns across 17 risk categories.
Best for: Security teams vetting agent skills; Developers installing third-party agent skills; Organizations implementing agent skill governance
4. LLM Guard
The Security Toolkit for LLM Interactions
Best for: Enterprise teams deploying LLMs in production needing security guardrails; Organizations with strict data leakage prevention requirements; Applications handling sensitive user data through LLM interfaces
5. Guardrails
NeMo Guardrails is an open-source toolkit for easily adding programmable guardrails to LLM-based conversational systems.
What sets it apart: Only framework offering 5-layer programmable guardrails (input/dialog/retrieval/execution/output) with a dedicated Colang scripting language, backed by NVIDIA
Best for: Enterprise LLM apps needing safety and compliance guardrails; Chatbots requiring strict topic control; RAG pipelines needing retrieval rail filtering
6. Superagent
Superagent protects your AI applications against prompt injections, data leaks, and harmful outputs. Embed safety directly into your app and prove compliance to your customers.
What sets it apart: YC-backed AI safety SDK that pivoted from general agent building to focused safety tooling — provides guard, redact, and scan capabilities with open-weight models for self-hosting, filling the gap between building agents and securing them
Best for: Teams adding safety layers to production AI agents; Enterprises requiring PII redaction and prompt injection protection; Security-focused AI deployments with compliance requirements
7. langwatch
The platform for LLM evaluations and AI agent testing
What sets it apart: Unified platform combining agent simulation, evaluation, observability, and prompt optimization with OpenTelemetry-native design — vs separate tools for tracing (Langfuse), eval (DeepEval), and prompt management
Best for: Teams wanting eval + observability + prompt management in one tool; Agent simulation testing before production deployment; Organizations needing OpenTelemetry-native LLM observability
8. Opik
Debug, evaluate, and monitor your LLM applications, RAG systems, and agentic workflows with comprehensive tracing, automated evaluations, and production-ready dashboards.
What sets it apart: Full-lifecycle LLM platform combining tracing, evaluation, and optimization — uniquely includes Agent Optimizer and Guardrails alongside observability, unlike trace-only tools like LangSmith
Best for: Teams needing end-to-end LLM observability from development to production; Automated LLM evaluation and quality assurance in CI/CD pipelines
FAQ
- What are the best alternatives to garak?
- The closest open-source alternatives to garak are Promptfoo, agentic-radar and SkillSpector, followed by LLM Guard, Guardrails and Superagent. They are ranked by how closely they match what garak does.
- Which garak alternative is the most popular?
- Promptfoo has the most GitHub stars among garak alternatives, with 25,597 stars.
- Which garak alternative is the most actively maintained?
- By recent activity, langwatch (1,556 commits in the last 90 days) is the most actively developed alternative.