Skip to content
aicoolies logo
garak logo

garak

NVIDIA's LLM vulnerability scanner and red-teaming tool

garak is NVIDIA's open-source LLM vulnerability scanner for red-teaming AI models and applications. Probes for prompt injection, data leakage, hallucination, toxicity, encoding-based attacks, and dozens of other vulnerability categories. Runs automated attack sequences against any LLM endpoint and generates detailed vulnerability reports. Features a modular probe/detector architecture that is extensible with custom attack patterns. Named after the Star Trek character known for deception.

About garak

garak is NVIDIA's open-source tool for LLM red-teaming and vulnerability scanning. Named after the deceptive Star Trek character, it systematically probes AI models for security weaknesses, biases, and failure modes.

The tool runs automated attack sequences including prompt injection attempts, jailbreak patterns, data extraction probes, encoding-based bypasses, toxicity elicitation, hallucination triggers, and dozens of other vulnerability categories drawn from AI security research.

A modular architecture separates probes (attack generators), detectors (vulnerability identifiers), and generators (target model interfaces). This makes it extensible — researchers and security teams can add custom attack patterns specific to their applications.

garak works with any LLM endpoint including OpenAI, Anthropic, Hugging Face models, and local deployments. It generates detailed vulnerability reports scoring each model across attack categories, enabling systematic comparison of model security postures before deployment.

Pricing & Platform Specs

Pricing Summary

garak is a 100% open-source LLM vulnerability scanner developed by NVIDIA and the open-source community, released under the Apache 2.0 license. It is completely free to use and automate in CI/CD pipelines.

Supported Platforms

Python, CLI, any LLM endpoint

Explore categories, tags & use cases

Security scanner for MCP servers against tool poisoning attacks

MCP-Scan is a security tool that scans MCP servers for vulnerabilities including tool poisoning, prompt injection, cross-origin escalation, and rug pull attacks. Acquired by Snyk in 2026, it is the first dedicated security scanner for the MCP ecosystem. It analyzes tool descriptions, permissions, and behavior patterns to detect malicious or compromised MCP servers before they can exploit AI agents.

Open Source

Open-source LLM red-teaming framework with 40+ attack types

DeepTeam is an open-source red-teaming framework for systematically testing LLM applications against 40+ adversarial attack types. It covers OWASP Top 10 for LLMs including jailbreaks, prompt injection, PII leakage, and hallucination attacks. Built as the sister project of DeepEval for security testing alongside evaluation. Apache-2.0 licensed.

freemiumOpen Source

Autonomous AI pentester for web apps and APIs

Shannon is an autonomous white-box AI pentesting tool for web applications and APIs. It analyzes authorized source code, identifies attack vectors, attempts proof-by-exploitation, and produces remediation-ready reports. Shannon Lite is AGPL-3.0 for local use, while Shannon Pro is the commercial Keygraph platform for continuous security testing.

freemiumOpen Source

Google's vulnerability scanner using the OSV database

OSV-Scanner is Google's official open-source vulnerability scanner that checks your project's dependencies against the OSV.dev database — the largest open vulnerability database covering all major ecosystems. Written in Go, it supports lockfiles from npm, pip, Maven, Cargo, Go modules, and more, providing actionable remediation guidance and CI/CD integration for automated security scanning.

Open Source

Side-by-Side Comparisons

Promptfoo logo
Promptfoo
vs
garak logo
garak

Promptfoo vs garak: CI Security Gates or Model Probes?

Promptfoo is the stronger default for teams that need repeatable LLM quality and security checks inside delivery pipelines, while garak remains a focused choice for broad model-level vulnerability probing. Promptfoo wins because it turns findings into configurable regression gates without giving up red-team coverage.

Shannon logo
Shannon
vs
garak logo
garak

Shannon vs Garak — AI Penetration Tester vs LLM Vulnerability Scanner

Shannon and Garak both address AI security but from completely different angles. Shannon is an autonomous pentester that attacks web applications and APIs to find real vulnerabilities, while Garak probes LLM models themselves for prompt injection, jailbreaks, and alignment failures. They are complementary tools targeting different layers of the AI application stack.

Shannongarak
ps-fuzz logo
ps-fuzz
vs
garak logo
garak
vs
NVIDIA logo
NeMo Guardrails

ps-fuzz vs Garak vs NeMo Guardrails — Prompt Injection Testing & LLM Security Tools Compared

As LLM-powered applications become production staples, prompt injection and jailbreak attacks represent some of the most dangerous threat vectors. Developers need tools that can systematically test their systems against these attacks before deployment. This comparison examines three distinct approaches to LLM security: ps-fuzz for targeted prompt fuzzing, Garak for comprehensive vulnerability scanning, and NeMo Guardrails for runtime protection and enforcement.

ModelScan logo
ModelScan
vs
LLM Guard logo
LLM Guard
vs
garak logo
garak

ModelScan vs LLM Guard vs Garak — AI Model Security Comparison

AI model security addresses threats at different layers of the ML lifecycle. ModelScan from Protect AI detects malicious code embedded in serialized model files before deployment, protecting against model supply chain attacks. LLM Guard acts as a real-time firewall for LLM applications, scanning prompts and responses to block injection attacks and data leakage. Garak is an LLM vulnerability scanner that probes models for weaknesses through automated red-teaming and adversarial testing.

View 1 more comparisons

Community experience

Sources & verification

Sources checked
Content verified

Verification dates are editorial checks. Routine CMS saves and automatic updatedAt timestamps do not advance them.

FAQ

What is garak?

garak is NVIDIA's open-source LLM vulnerability scanner for red-teaming AI models and applications. Probes for prompt injection, data leakage, hallucination, toxicity, encoding-based attacks, and dozens of other vulnerability categories. Runs automated attack sequences against any LLM endpoint and generates detailed vulnerability reports. Features a modular probe/detector architecture that is extensible with custom attack patterns. Named after the Star Trek character known for deception.

Is garak free?

Yes — garak is free to use. garak is a 100% open-source LLM vulnerability scanner developed by NVIDIA and the open-source community, released under the Apache 2.0 license. It is completely free to use and automate in CI/CD pipelines.

Is garak open source?

Yes — garak is open source.

Is garak still maintained?

Yes — garak is active. Its listing was last verified on August 26, 2026.

What are the best garak alternatives?

The first editor-selected garak alternatives are MCP-Scan, DeepTeam, Shannon, and more.