garak
NVIDIALLM vulnerability scanner maintained by NVIDIA. It probes models for hallucination, data leakage, prompt injection, misinformation, toxicity generation and jailbreaks across many providers including Hugging Face, OpenAI and Bedrock, run from the command line against your own endpoints.
Verified 2026-08-13 via GitHub.
Openness
5 high confidence- license
- Apache-2.0(OSI)
- source
- public
- self-host
- yes
- service
- none
- core-gated
- ungated
Fully open source: Apache-2.0 scanner, self-hostable, no proprietary tier.
- https://github.com/NVIDIA/garak recorded 2026-08-13
Repo metadata records license spdxId - Apache-2.0. The README is a command-line Get Started for running the scanner locally against your own model endpoints; there is no hosted tier, no enterprise directory and no license key on the page, so nothing is withheld from the published source.
Adoption
2 low confidence8,783 GitHub stars on NVIDIA/garak, which bands at 1K-10K stars, level 2. No download, install or customer figure is published for this product, so stars are the only honest signal and the level is directional; a stars proxy never rises above 3, because a star is not a use.
- https://api.github.com/repos/NVIDIA/garak recorded 2026-08-12
stargazers_count = 8,783 for NVIDIA/garak
Capability
4 medium confidenceBroadest open library of LLM vulnerability probes; multi-provider coverage.
- https://github.com/NVIDIA/garak recorded 2026-08-13
README states 'garak probes for hallucination, data leakage, prompt injection, misinformation, toxicity generation, jailbreaks, and many other weaknesses' and positions it as nmap for LLMs, with named probe modules including promptinject and realtoxicityprompts.
Verified 2026-08-12