g

garak

the LLM vulnerability scanner

9.4k
Stars
+783
Stars/month
225
Commits (90d)
4
Releases (6m)

Star Growth

+2.3k (33.3%)estimated from velocity
6.9k8.2k9.6kJul 2Sep 30

Overview

Garak is a free, open-source tool that probes LLMs and dialog systems for vulnerabilities like hallucination, data leakage, prompt injection, misinformation, toxicity, and jailbreaks. It uses static, dynamic, and adaptive probes to test for failures, similar to security tools like nmap or Metasploit but for generative AI models. The tool supports a wide range of LLMs including Hugging Face, OpenAI API, AWS Bedrock, Replicate, and local GGUF models.

Deep Analysis

Key Differentiator

Specialized security-focused evaluation framework that treats LLM assessment like traditional vulnerability scanning with nmap/Metasploit methodologies.

⚡ Capabilities

  • • LLM vulnerability scanning
  • • red-teaming probes for hallucination, data leakage, prompt injection
  • • toxicity and misinformation detection
  • • jailbreak testing
  • • static, dynamic, and adaptive assessment

🔗 Integrations

Hugging Face HubOpenAI APIAWS BedrockReplicateLiteLLMGGUF models (llama.cpp)REST APIs

✓ Best For

  • ✓ Security testing of LLM-based agents
  • ✓ Evaluating agent robustness before deployment
  • ✓ Red-teaming AI agent vulnerabilities

✗ Not Ideal For

  • ✗ Building or running production agents
  • ✗ End-user chatbot interfaces
  • ✗ Generic AI content generation

⚠ Known Limitations

  • ⚠ Command-line tool only
  • ⚠ Focuses on finding failures rather than building functionality
  • ⚠ Requires technical setup for various LLM integrations

Alternatives

See all 8 garak alternatives →

Works with garak

Tools that integrate with garak, often used together in the same stack.

Compare garak

Maintain garak?

Show your live rank in your README, or put garak in front of every visitor to AgentoolRank.