{"categories":[{"label":"Security","url":"https://skillfed.io/packages/category/security/3"}],"enrichment":{"capability":"Garak is a command-line tool that probes large language models for security vulnerabilities, testing for hallucination, data leakage, prompt injection, misinformation, toxicity, jailbreaks, and other failure modes.","skillfed_tags":["llm-security","red-teaming","vulnerability-assessment"],"use_cases":["Test a commercial LLM API (OpenAI, Cohere, Anthropic) for susceptibility to prompt injection or encoding-based attacks before deploying it in production.","Evaluate a locally-hosted Hugging Face model for jailbreak vulnerabilities or toxicity generation as part of a model selection process.","Run a comprehensive probe suite against a custom LLM endpoint to identify which vulnerability classes it is most susceptible to.","Automate security regression testing on LLM updates to detect newly introduced failure modes or weakened defenses.","Generate detailed vulnerability reports for compliance, risk assessment, or responsible AI documentation."],"what_it_does":"Garak is a red-teaming and vulnerability assessment toolkit for large language models. It works like a security scanner (similar in spirit to nmap or Metasploit, but for LLMs) by running static, dynamic, and adaptive probes against a target model to uncover ways it can fail or behave undesirably. It supports a wide range of LLM sources\u2014Hugging Face Hub models, OpenAI, Anthropic, Cohere, Replicate, AWS Bedrock, and REST-accessible endpoints\u2014and can test local models or remote APIs.\n\nThe tool combines multiple probe frameworks and detectors to check for specific vulnerabilities: prompt injection attacks, hallucination, data leakage, jailbreaks, toxicity generation, misinformation, and others. It generates test prompts, collects model responses, and evaluates them against detectors to produce a report showing which probes succeeded and the failure rate for each. Results are logged in detail to JSON and a summary log, making it suitable for both one-off security checks and systematic vulnerability assessment workflows.","worth_installing":"Yes, with conditions. Garak is actively maintained, has low install friction, and fills a clear niche in LLM security testing. However, the unclear license status requires verification before use in commercial or restricted contexts. The large dependency footprint (45 runtime packages including torch and multiple LLM SDKs) means it is best suited to dedicated security testing environments rather than lightweight integrations. Install it if you need systematic LLM vulnerability assessment; skip it if you need a minimal, license-transparent tool or have strict dependency constraints."},"id":"garak","links":{"html":"https://skillfed.io/packages/garak","md":"https://skillfed.io/packages/garak.md","pypi":"https://pypi.org/project/garak/"},"maintenance":{"status":"active"},"meta":{"latest_release":"2026-08-04","license_spdx":null,"license_treatment":"unclear","name":"garak","python_support":"supports_current","summary":"LLM vulnerability scanner"},"popularity":{"monthly_downloads":80181,"position":14311,"tier":"top_15000"},"security":{"n_vulnerabilities":0},"version":"0.16.0"}
