Skip to content
aicoolies logo
ps-fuzz logo

ps-fuzz

Prompt fuzzing tool for LLM security testing

ps-fuzz by Prompt Security is a security testing tool with 680+ GitHub stars that fuzzes system prompts against dynamic LLM-based attack scenarios including jailbreaks, prompt injection, and data extraction attempts. It helps developers harden their GenAI applications by simulating adversarial attacks in a controlled environment, turning LLM security into a testable and reproducible quality gate.

About ps-fuzz

ps-fuzz automates the security testing of GenAI applications by subjecting system prompts to a comprehensive suite of attack simulations. The tool generates dynamic adversarial inputs covering jailbreak attempts, prompt injection techniques, data extraction attacks, and system prompt leakage scenarios. Each test produces a detailed report showing which attacks succeeded and which defenses held, giving developers concrete guidance on where to strengthen their prompt engineering.

The testing approach treats prompt security like traditional fuzzing: systematically exploring edge cases and attack surfaces that manual testing would miss. Teams can integrate ps-fuzz into CI/CD pipelines to run prompt security regression tests whenever system prompts are modified, catching regressions before they reach production. This transforms LLM security from an ad-hoc concern into a structured, automated quality gate.

With 680+ GitHub stars and project activity into 2026, ps-fuzz addresses the growing need for practical LLM security testing tools. As organizations deploy more AI-powered features, the attack surface for prompt injection and related vulnerabilities expands rapidly. The tool is developed by Prompt Security, a company focused on GenAI security, and serves both security researchers and application developers building with LLMs.

Pricing & Platform Specs

Pricing Summary

100% open-source AI security fuzzer (MIT License) with $0 software license fees. Unlimited local and CI/CD automated prompt injection, jailbreak, and system prompt leakage vulnerability testing; users only incur standard LLM API provider token inference costs (BYOK). Prompt Security also provides a separate enterprise AI security platform (SentinelOne) via custom enterprise quote.

full pricing breakdown →

Supported Platforms

Python CLI, CI/CD pipelines

Explore categories, tags & use cases

Prompt registry, observability, and evaluation workflows for LLM applications.

PromptLayer is a prompt management, observability, and evaluation platform for LLM applications. Teams use its Prompt Registry, visual editor, request logs, Tables, evaluations, Tool Registry, and Skill Collections to version prompts, replay requests, compare variants, run datasets, and ship prompt changes without redeploying code. Pricing starts with Free $0 for 5 users and 2.5K requests/month, Pro $49/month, Team $500/month, and Enterprise custom.

freemium

Validate and structure LLM outputs with composable Guards

Guardrails AI is an open-source Python and JavaScript framework for validating and structuring LLM outputs using composable Guards built from a Hub of pre-built validators. It handles structured data extraction with Pydantic models, content safety checks including toxicity, PII detection, competitor mentions, and bias filtering, plus automatic re-prompting when validation fails. The Guardrails Hub offers dozens of validators from regex matching to hallucination detection via LLM judges.

Open Source

Programmable safety rails for LLM applications

NeMo Guardrails is NVIDIA's open-source toolkit for adding programmable safety rails to LLM applications. It supports five guardrail types — input, dialog, retrieval, execution, and output rails — covering content safety, jailbreak detection, topic control, PII masking, hallucination detection, and fact-checking. The toolkit uses Colang, a domain-specific language for defining conversational constraints, and integrates with OpenAI, Azure, Anthropic, HuggingFace, and LangChain/LangGraph.

Open Source

Side-by-Side Comparisons

ps-fuzz logo
ps-fuzz
vs
garak logo
garak
vs
NVIDIA logo
NeMo Guardrails

ps-fuzz vs Garak vs NeMo Guardrails — Prompt Injection Testing & LLM Security Tools Compared

As LLM-powered applications become production staples, prompt injection and jailbreak attacks represent some of the most dangerous threat vectors. Developers need tools that can systematically test their systems against these attacks before deployment. This comparison examines three distinct approaches to LLM security: ps-fuzz for targeted prompt fuzzing, Garak for comprehensive vulnerability scanning, and NeMo Guardrails for runtime protection and enforcement.

Community experience

Sources & verification

Sources checked
Content verified

Verification dates are editorial checks. Routine CMS saves and automatic updatedAt timestamps do not advance them.

FAQ

What is ps-fuzz?

ps-fuzz by Prompt Security is a security testing tool with 680+ GitHub stars that fuzzes system prompts against dynamic LLM-based attack scenarios including jailbreaks, prompt injection, and data extraction attempts. It helps developers harden their GenAI applications by simulating adversarial attacks in a controlled environment, turning LLM security into a testable and reproducible quality gate.

Is ps-fuzz free?

Yes — ps-fuzz is open source and free to use. 100% open-source AI security fuzzer (MIT License) with $0 software license fees. Unlimited local and CI/CD automated prompt injection, jailbreak, and system prompt leakage vulnerability testing; users only incur standard LLM API provider token inference costs (BYOK). Prompt Security also provides a separate enterprise AI security platform (SentinelOne) via custom enterprise quote.

Is ps-fuzz open source?

Yes — ps-fuzz is open source.

Is ps-fuzz still maintained?

Yes — ps-fuzz is active. Its listing was last verified on September 6, 2026.

What are the best ps-fuzz alternatives?

The first editor-selected ps-fuzz alternatives are PromptLayer, Guardrails AI, NeMo Guardrails.

How does ps-fuzz score in our review?

The published editorial review lists ps-fuzz at 72/100 overall across speed, privacy, and developer experience. Check the review's evidence status and test metadata for its verification level.