Skip to content
AI Tool

garak Review

garak is an open-source LLM vulnerability scanner designed for security testing of large language models against various risks.

shipped Sep 30, 2026codefree
Domain rating47Monthly visits601/mo
code
garak — product screenshot

Why it matters

1Open-source LLM vulnerability scanner with over 120 probe categories.
2Actively maintained by NVIDIA and the community, with v0.17.0 released September 9, 2026.
3Used and recommended by Microsoft, Trend Micro, NVIDIA, and Cisco.
4GitHub repository has over 8,100 stars, 777 forks, and 71 contributors.

Specs

API Available

Yes, public API

overview

What is garak?

garak is an LLM vulnerability scanner tool developed by NVIDIA that enables security professionals and developers to identify security flaws and unwanted behaviors in Large Language Models (LLMs). It functions as a command-line toolkit for red-teaming and systematically probing models against various adversarial conditions before deployment.

features

Key Features of garak

garak provides a comprehensive framework for LLM security testing, leveraging a modular architecture to identify a wide range of vulnerabilities. Its features are designed for extensibility and integration into existing security workflows.

  • Open-source LLM vulnerability scanner
  • Framework for identifying LLM vulnerabilities through probes
  • Command-line interface for security testing
  • Actively updated by NVIDIA and the community
  • Provides documentation and community support
  • GitHub issues actively responded to and addressed
  • Modular plugin architecture for custom probes
  • Supports JSON and YAML configuration for CI pipelines
  • Redesigned HTML reports for output visualization
  • Includes multi-turn GOAT and Agent-breaker probes (v0.15.0)

use cases

Who Should Use garak?

garak is primarily designed for security engineers, AI developers, and red-teamers focused on ensuring the robustness and safety of Large Language Models. Its capabilities support various stages of the LLM lifecycle, from pre-deployment to continuous assessment.

  • Security Testing of LLMs: Professionals assessing the security posture of large language models.
  • Pre-deployment LLM Security Testing: Identifying critical issues before models are deployed in real-world applications.
  • Red-teaming AI Applications: Simulating attacks to understand LLM behavior under adversarial conditions.
  • Compliance Testing: Ensuring LLM deployments meet safety and ethical standards.
  • Regression Testing: Comparing new results against a baseline after changes to system prompts, guardrails, or model providers.

how to use

How to Use garak

garak operates as a command-line tool, allowing users to configure and execute adversarial probes against LLMs or LLM-powered systems. Its usage involves selecting probes, specifying target models, and analyzing the generated outputs.

  • 1Install garak via pip or clone the GitHub repository.
  • 2Configure the target LLM or endpoint using supported generators.
  • 3Select specific probes from the library (e.g., prompt injection, jailbreaks).
  • 4Run garak from the command line to execute probes and apply detectors.
  • 5Review the generated reports (e.g., HTML) to identify vulnerabilities and attack success rates.
  • 6Utilize documentation and community support for advanced configurations and custom probe development.

pricing

garak Pricing & Plans

garak is an open-source project released under the Apache 2.0 License. It is available for free, with active development and community support provided by NVIDIA and its contributors.

  • Free: Open-source software, actively updated, community support, documentation access.

Enjoying this? Get one like it in your inbox each morning.

one email a day · unsubscribe in two clicks · no third-party tracking

Pros

  • +Extensive open-source probe library with over 120 vulnerability categories.
  • +Actively maintained by NVIDIA and a large community (8,100+ GitHub stars).
  • +Command-line interface suitable for integration into CI/CD pipelines.
  • +Supports a wide range of vulnerabilities including prompt injection, jailbreaks, and data leakage.
  • +Provides detailed HTML reports for vulnerability assessment.
  • +Free to use under the Apache 2.0 License.

Cons

  • −Primarily a command-line tool, which may require technical proficiency.
  • −Focuses on model-level and single-turn attacks, though multi-turn capabilities are evolving.
  • −Requires manual setup and configuration for specific LLM endpoints.
  • −While widely recommended, detailed user reviews on specific complaints are not broadly available.

Similar Tools

garak vs Competitors

garak is positioned as a specialist tool for adversarial probes and safety testing, focusing on LLM security rather than broad model benchmarking. It distinguishes itself through its extensive open-source probe library and modular architecture.

1
PyRIT (Python Risk Identification Toolkit)↗

Focuses on systematic, repeatable red teaming of generative AI systems with automation support, allowing for custom, adaptive, multi-turn attack campaigns.

While garak is a general-purpose vulnerability scanner with a wide range of probes, PyRIT emphasizes building custom, adaptive, multi-turn campaigns, which might require more setup for specific scenarios but offers deeper, more tailored testing.

2

Provides an open-source command-line workflow for generating and evaluating broad red-team scans, with a strong focus on customizing vulnerability probes specifically for your application.

Promptfoo offers a similar CLI-based red teaming approach to garak but highlights its ability to customize vulnerability probes for specific application use cases, potentially offering more tailored testing than garak's broader, configurable scans.

3
Augustus↗

Offers an extensive collection of over 210 adversarial probes across 47 attack categories, including various encoding attacks, jailbreaks, data extraction, and agent attacks.

While garak also provides a wide range of probes, Augustus specifically highlights its large, categorized probe library, potentially offering a more structured and comprehensive set of pre-built attacks for diverse LLM vulnerabilities.

4
OpenAnt↗

An LLM-based vulnerability discovery tool that integrates static program analysis with LLM reasoning to actively attack code and identify vulnerabilities before reporting them.

Unlike garak, which primarily focuses on LLM model behavior through adversarial prompts, OpenAnt uses LLMs to scan and attack *codebases* for vulnerabilities, offering a different, code-centric security assessment approach.

More on Stork

Related AI Tools

Other tools in this category, matched by shared tags

One short daily email of tools worth shipping. No drip funnel.

one email a day · unsubscribe in two clicks · no third-party tracking

For builders

This page is doing a job for someone else’s tool.

AI agents read it. Buyers land on it. It answers in eight languages and over MCP. Your tool can have one like it — live in 24 hours.