Skip to main content

garak

the LLM vulnerability scanner

View on GitHub Official site
Privacy Security Apache-2.0 Easy setup 8,526 stars

Overview

Description

Garak protects your business by automatically stress-testing LLM applications for security vulnerabilities before attackers can exploit them. It probes for jailbreaks, data leaks, prompt injection, hallucination, and dozens of other failure modes in a single automated scan. The bottom line: catch weaknesses early with the industry-standard penetration testing toolkit for language models.

Technical scorecard

License

Apache-2.0

Commercial use

Yes

OpenAI-compatible API

No

REST API

No

Fine-tuning support

No

Quantization support

No

Docker available

No

GUI / no-code available

No

Telemetry

Unknown

Offline after setup

Yes

Data & Privacy

Does it send data online?

After setup, this listing is marked as usable offline. Confirm network behavior against the upstream project before regulated deployment.

Does it store history?

Not verified in this directory yet. Review the upstream docs for persistence, logs, and workspace storage.

License checks?

Commercial use is marked as allowed or likely allowed by the listed license.

Telemetry?

Unknown

Last verified: Jul 22, 2026. Maintainer verification should be treated as directory guidance, not legal advice.

🛡️

Deploying garak in production?

Stop silent telemetry leaks before they trigger an unintended data leak. Get our Airgap Certainty Blueprint for garak.

Request Privacy and Telemetry Audit

Setup & Installation

Easy

A developer can usually get this running with standard docs.

# Start with the official project repository
# https://github.com/NVIDIA/garak

Hardware Requirements

Hardware tagsCPU, GPU (NVIDIA)
LanguagesPython, HTML

Works Well With