MCP-Scan is a security tool that scans MCP servers for vulnerabilities including tool poisoning, prompt injection, cross-origin escalation, and rug pull attacks. Acquired by Snyk in 2026, it is the first dedicated security scanner for the MCP ecosystem. It analyzes tool descriptions, permissions, and behavior patterns to detect malicious or compromised MCP servers before they can exploit AI agents.
Alternatives to garak
4 editor-selected alternatives · garak overview →
source: tools.alternatives · stored order · active records only; review scores are annotations and never change membership or order
A directional evidence panel appears only when the substitute rationale, trade-offs, sources, and verification date have been recorded. Older selections without that panel remain visible but are unclassified under the new evidence contract.
DeepTeam is an open-source red-teaming framework for systematically testing LLM applications against 40+ adversarial attack types. It covers OWASP Top 10 for LLMs including jailbreaks, prompt injection, PII leakage, and hallucination attacks. Built as the sister project of DeepEval for security testing alongside evaluation. Apache-2.0 licensed.
Shannon is an autonomous white-box AI pentesting tool for web applications and APIs. It analyzes authorized source code, identifies attack vectors, attempts proof-by-exploitation, and produces remediation-ready reports. Shannon Lite is AGPL-3.0 for local use, while Shannon Pro is the commercial Keygraph platform for continuous security testing.
OSV-Scanner is Google's official open-source vulnerability scanner that checks your project's dependencies against the OSV.dev database — the largest open vulnerability database covering all major ecosystems. Written in Go, it supports lockfiles from npm, pip, Maven, Cargo, Go modules, and more, providing actionable remediation guidance and CI/CD integration for automated security scanning.
Open-source garak alternatives
MCP-Scan, DeepTeam, Shannon, osv-scanner — see all open-source developer tools.
Free garak alternatives
More AI Security & DevSecOps tools
same category, not editor-selected alternatives — see how garak compares →
garak head-to-head
- Promptfoo vs garak: CI Security Gates or Model Probes? →
- Shannon vs Garak — AI Penetration Tester vs LLM Vulnerability Scanner →
- ps-fuzz vs Garak vs NeMo Guardrails — Prompt Injection Testing & LLM Security Tools Compared →
- ModelScan vs LLM Guard vs Garak — AI Model Security Comparison →
- Lakera vs garak — LLM Security Tool Comparison →
FAQ
Which garak alternative is listed first?
MCP-Scan is first in the editor-selected list of 4 garak alternatives and carries an editorial review score of 90/100. The stored order is editorial; review scores do not determine membership or position.
Are there open-source garak alternatives?
Yes — MCP-Scan, DeepTeam, Shannon, and more are open source.
Are there free garak alternatives?
Yes — DeepTeam, Shannon offer a free plan or free tier.