verifier.org

Garak

apache 2.0 from nvidia, twenty-plus probe modules, and a peer-reviewed paper behind it.

free#scanning-a-specific-mode#with-something-citable-t

the most rigorous free option and the narrowest in scope — it tests a model beautifully and knows nothing about the application around it.

apache 2.0, maintained under nvidia's github organisation with leon derczynski as co-copyright holder, and backed by a peer-reviewed preprint on arxiv that users are asked to cite. in a category where most vendors publish marketing copy, having a paper to point at is a meaningful difference.

the probe coverage is broad for model-level work: hallucination, data leakage, prompt injection, misinformation, toxicity, jailbreaks including dan-style attacks, encoding-based injection, malware generation, package hallucination and xss-style output, across more than twenty modules. it runs from the command line against a named target model with no account and no sales contact.

the description above is ours, condensed from the ranking. pricing moves — check it on the vendor's own page before you rely on it.

pricing
free
website
github.com
our verdict

the most rigorous free option and the narrowest in scope — it tests a model beautifully and knows nothing about the application around it.

we researched this category against vendors' own pricing pages and licence files. that is where this line comes from — not from the vendor, and not from anything they paid for.

more ai red-teaming tools

NeMo Guardrails

nvidia's toolkit for constraining llm behaviour, used alongside testing

#guardrails#open-source

Giskard

open-source scanner for llm vulnerabilities and quality regressions

#open-source#scanner

ModelScan

scans model files for unsafe serialisation before you load them

#supply-chain#open-source

HiddenLayer

we checked thisnot published

fifty disclosed cves and thirty patents, across the broadest claimed scope here.

#enterprises-wanting-mode