Tool overview
Garak is listed under AI Governance Safety & Evaluation AI tools.
What is Garak?
garak is NVIDIA-supported open-source software for testing language models and dialog systems against prompt injection, data leakage, hallucination, misinformation, toxicity, jailbreaks, and other failure modes. It runs as a local Python command-line tool and supports many model providers and custom REST-accessible generators.
Best for
Security and AI teams testing language-model failure modes in controlled environments
Who is it for?
Decision note
Accepted for Preview after independent V411 official-source research. Apply only after failures = 0, warnings = 0, unmapped = 0, and review of controlled fields, Arabic v2 parity, outreach, affiliate status, logo QA, rebrand handling, and explicit clears.
Key features
Static, dynamic, and adaptive vulnerability probes
Command-line scanning and reporting
Support for hosted and local model generators
Extensible detectors, probes, and harnesses
Use cases
Testing prompt-injection resistance
Scanning for data leakage and jailbreaks
Comparing model safety behavior
Integrating LLM tests into security workflows
Pros
- Free under Apache-2.0
- Broad model-provider support
- Maintained with NVIDIA contribution
Limitations
garak does not prove that a model or application is secure. Coverage depends on selected probes, model settings, target permissions, and detector quality. Users must obtain authorization, prevent harmful output exposure, control costs, and combine scanning with broader threat modeling and review.
Pricing details
Billing options
Free open-source software
Pricing note
garak is free open-source software under Apache-2.0. There is no paid hosted plan or trial. Users remain responsible for model API charges, local compute, storage, security review, and any infrastructure used to run scans.
Supported languages
- English
Integrations
OpenAI
Hugging Face
Replicate
AWS Bedrock
LiteLLM
REST generators
Please log in to join the discussion.