garak checks if an LLM can be made to fail in a way we don't want. garak probes for hallucination, data leakage, prompt injection, misinformation, toxicity generation, jailbreaks, and many other weaknesses. If you know nmap or msf / Metasploit Framework, garak does somewhat similar things to them, but for LLMs. garak focuses on ways of making an LLM or dialog system fail. It combines static, dynamic, and adaptive probes to explore this.
from the project README
Formats
python
License
Apache-2.0
Added
2026-09-10
Get it
From the project’s own instructions where it documents any; otherwise a plain clone.
shell
$ python -m pip install -U garak
Its probe library is the dataset — jailbreak, prompt-injection, encoding and data-leak attacks against an LLM.
Contents
874 files15.6 MB repository
.py373
.rst153
.json69
.ts61
.tsx57
.txt50
.md19
.jsonl15
Use it with
Commands are curated, not yet run by us.
Inspect AI — Run an Inspect task file; the benchmark has to be wrapped as an Inspect task first.