garak
Community project
garak is an Apache-2.0 open-source command-line vulnerability scanner for generative AI systems. It runs probes and detectors against supported model interfaces to test failure modes including prompt injection, data leakage, hallucination, misinformation, toxicity, and jailbreaks.
Verified Sources: garak.ai, github.com
- Product type
- Community project
- Deployment
- CLI
- Organization size
- IndividualSMBMid-marketEnterprise
- Pricing tier
- Free
AI security profile
Open-source command-line vulnerability scanner that probes language models for prompt injection, data leakage, jailbreaks, toxicity, and other failure modes.
Capability checklist
AI Red TeamingHow garak measures up against the full AI Security Testing & Model Assurance taxonomy.
- AI red teaming — supported
- Runs adversarial tests against models and applications to uncover exploitable or unsafe behavior.
- Prompt-injection testing — supported
- Tests whether untrusted instructions can override intended system behavior or controls.
- Jailbreak & safety testing — supported
- Evaluates resistance to policy bypasses, harmful outputs, and other unsafe behaviors.
- Model artifact scanning — not supported
- Inspects model files and serialized artifacts for malicious code, tampering, and unsafe components.
- AI supply-chain assurance — not supported
- Tracks model provenance, dependencies, integrity, and risk before deployment.
- Continuous AI evaluation — supported
- Repeats security tests as models, prompts, tools, data, and application behavior change.
Alternatives
Other AI Security Testing & Model Assurance tools with overlapping capabilities, sized for similar teams.
Head-to-head comparisons
Source-linked comparisons featuring garak.
Appears in stacks
Real-world stacks that include garak.