Red-Teaming LLMs with garak
Legal and Authorized-Use Notice: This skill is for authorized AI security testing and educational purposes only. Probe only models, API keys, and endpoints you own or have explicit written permission to test. Automated probing of third-party LLM APIs may violate their terms of service and consume billable tokens. Unauthorized probing of systems you do not control may be illegal.
Overview
garak (Generative AI Red-teaming and Assessment Kit) is an open-source LLM vulnerability scanner maintained by NVIDIA. It plays the role that a network vulnerability scanner like Nessus plays for hosts, but for large language models: it sends thousands of adversarial prompts ("probes") at a target model, captures the generations, and runs automated "detectors" over the responses to decide whether each attempt succeeded. Probe families cover prompt injection (promptinject, latentinjection), jailbreaks (dan), training-data and system-prompt leakage (leakreplay), malware generation (malwaregen), cross-site-scripting payload emission (xss), encoding-based bypasses (encoding), toxicity, and more. garak is described in the paper "garak: A Framework for Security Probing Large Language Models" (arXiv:2406.11036) and is distributed from the NVIDIA/garak GitHub repository.
The scanner is generator-agnostic. It can target Hugging Face models loaded locally, OpenAI-compatible APIs, AWS Bedrock, Replicate, Cohere, NIM endpoints, GGUF/llama.cpp models, and arbitrary REST endpoints via a JSON generator spec. After a run, garak emits a .report.jsonl line-delimited log of every attempt and detector verdict, a human-readable .report.html, a garak.log debug log, and a hit log of confirmed vulnerabilities. The terminal output prints a per-probe, per-detector pass/fail summary with a hit rate (for example dan.Dan_11_0 jailbreak: FAIL ok on 38/40), which is the primary artifact you interpret.
This skill maps to the MITRE ATLAS techniques AML.T0051 (LLM Prompt Injection) and AML.T0054 (LLM Jailbreak) because garak operationalizes both: it crafts prompt-injection and jailbreak inputs at scale and measures whether the target's guardrails hold. It supports the NIST AI RMF MEASURE-2.7 subcategory by providing repeatable, quantitative security/resilience measurement of a deployed AI system.
When to Use
- When you need a fast, repeatable baseline security assessment of an LLM before or after deployment.
- When validating that a guardrail, system prompt, or safety fine-tune actually reduces jailbreak and injection success rates (run before/after and compare hit rates).
- When producing evidence for an AI risk assessment or model card security section (NIST AI RMF MEASURE-2.7).
- When triaging which OWASP LLM Top 10 risks (LLM01 prompt injection, LLM02 sensitive information disclosure, LLM07 system prompt leakage) actually manifest in your model.
- When regression-testing an LLM endpoint in CI after model or prompt changes.
Prerequisites
Objectives
- Enumerate available probes and detectors and pick a scoped suite.
- Configure garak against a local Hugging Face model, an OpenAI-compatible API, and an arbitrary REST endpoint.
- Run prompt-injection, jailbreak, and leakage probe families and capture reports.
- Interpret the per-probe hit-rate output and the
.report.jsonl.
- Re-run after applying a mitigation to demonstrate risk reduction.
- Produce a defensible findings artifact for an AI risk assessment.
MITRE ATT&CK Mapping
This skill uses MITRE ATLAS (the adversarial-ML companion to ATT&CK) technique IDs.
| ID |
Tactic |
Official Name |
Relevance |
| AML.T0051 |
ML Attack Staging / Impact |
LLM Prompt Injection |
garak's promptinject and latentinjection probes craft malicious prompts that subvert intended model behavior. |
| AML.T0054 |
Privilege Escalation / Defense Evasion |
LLM Jailbreak |
garak's dan and related probes attempt to bypass safety guardrails so the model produces restricted content. |
Workflow
Phase 1: Enumerate Probes and Detectors
- List every probe garak ships so you can scope the run:
garak --list_probes
- List detectors (the modules that score whether a probe succeeded) and generators (target connectors):
garak --list_detectors
garak --list_generators
- Read the probe taxonomy. Key families:
promptinject — PromptInject-framework direct injection.
latentinjection — instructions hidden in documents/encoded text (indirect injection).
dan — "Do Anything Now" and related jailbreaks (e.g. dan.Dan_11_0).
leakreplay — coax the model into reproducing memorized/training or hidden-prompt text.
encoding — base64/ROT13/etc. injection bypasses.
xss — emit cross-site-scripting payloads (markdown/HTML exfil).
malwaregen — request AV-evading or malicious code.
Phase 2: Probe a Local Hugging Face Model
- Run a single jailbreak probe against a local model to validate setup:
python -m garak --target_type huggingface --target_name gpt2 --probes dan.Dan_11_0
- Run a fuller suite against a chat model:
python -m garak \
--target_type huggingface \
--target_name meta-llama/Llama-3.2-1B-Instruct \
--probes promptinject,dan,leakreplay \
--report_prefix llama32_baseline
Phase 3: Probe an OpenAI-Compatible API
- Export the key and run injection + leakage probes:
export OPENAI_API_KEY="sk-..."
python -m garak \
--target_type openai \
--target_name gpt-4o-mini \
--probes promptinject,latentinjection,leakreplay \
--generations 5 \
--parallel_attempts 8 \
--report_prefix gpt4omini_injection
--generations controls how many completions per prompt (more = more statistical confidence, more cost).
--parallel_attempts raises throughput for remote APIs.
Phase 4: Probe an Arbitrary REST Endpoint
- garak can target any HTTP API via a JSON generator spec. Create
rest.json:{
"rest": {
"RestGenerator": {
"name": "my-llm-gateway",
"uri": "https://llm.internal.example/v1/chat",
"method": "post",
"headers": { "Authorization": "Bearer $ENV_TOKEN", "Content-Type": "application/json" },
"req_template_json_object": { "model": "internal-bot", "prompt": "$INPUT" },
"response_json": true,
"response_json_field": "$.output"
}
}
}
- Run garak against it:
export ENV_TOKEN="..."
python -m garak \
--target_type rest \
-G rest.json \
--probes promptinject,dan \
--report_prefix internal_gateway
Phase 5: Run a Curated Config and Full Sweep
- For repeatable assessments, pin everything in a YAML/JSON config and pass
--config:python -m garak --config assessment.yaml
# assessment.yaml
plugins:
model_type: openai
model_name: gpt-4o-mini
probe_spec: promptinject,latentinjection,dan,leakreplay,xss,malwaregen
run:
generations: 5
parallel_attempts: 8
reporting:
report_prefix: quarterly_llm_assessment
- For an exhaustive sweep (slow, expensive) run all probes by omitting
--probes entirely.
Phase 6: Interpret the Hit-Rate Report
- Read the terminal summary. Each row is
probe.Class detector: PASS|FAIL ok on N/M. A FAIL with a low ok fraction means the model frequently produced the unsafe behavior — a high-severity finding.
- Open the machine-readable report and aggregate failures:
# Every attempt with detector verdicts is one JSON line
jq -r 'select(.entry_type=="eval") | "\(.probe)\t\(.detector)\t\(.passed)/\(.total)"' \
garak.<timestamp>.report.jsonl | sort
- Open the generated
.report.html in a browser for the formatted scorecard and per-probe breakdown.
- Pull the actual successful attack strings from the hit log to use as proof-of-concept evidence.
Phase 7: Mitigate and Re-Test
- Apply a control (tighten the system prompt, add an input/output guardrail such as Llama Guard or LLM Guard, or change the model).
- Re-run the identical probe set with a new
--report_prefix.
- Compare hit rates between runs to quantify risk reduction for the report.
Tools and Resources
Probe Family Reference
| Probe family |
Targets |
OWASP LLM mapping |
promptinject |
Direct prompt injection |
LLM01 |
latentinjection |
Indirect / hidden-context injection |
LLM01 |
dan |
Jailbreak / guardrail bypass |
LLM01 / safety |
leakreplay |
Training-data & prompt leakage |
LLM02 / LLM07 |
encoding |
Encoding-based filter bypass |
LLM01 |
xss |
Markdown/HTML exfiltration payloads |
LLM02 |
malwaregen |
Malicious code generation |
misuse |
Validation Criteria
1---2name: red-teaming-llms-with-garak3description: Runs NVIDIA garak probe suites (jailbreak, prompt injection, data leakage, toxicity, and more) against an LLM endpoint - Hugging Face models, OpenAI-compatible APIs, or Bedrock - then interprets the resulting hit-rate report for triage. Use when baselining LLM security before/after deployment, validating that a guardrail or fine-tune reduces jailbreak/injection success rates, or producing evidence for an AI risk assessment.4license: Apache-2.05---6# Red-Teaming LLMs with garak
7
8> **Legal and Authorized-Use Notice:** This skill is for authorized AI security testing and educational purposes only. Probe only models, API keys, and endpoints you own or have explicit written permission to test. Automated probing of third-party LLM APIs may violate their terms of service and consume billable tokens. Unauthorized probing of systems you do not control may be illegal.
9
10## Overview
11
12garak (Generative AI Red-teaming and Assessment Kit) is an open-source LLM vulnerability scanner maintained by NVIDIA. It plays the role that a network vulnerability scanner like Nessus plays for hosts, but for large language models: it sends thousands of adversarial prompts ("probes") at a target model, captures the generations, and runs automated "detectors" over the responses to decide whether each attempt succeeded. Probe families cover prompt injection (`promptinject`, `latentinjection`), jailbreaks (`dan`), training-data and system-prompt leakage (`leakreplay`), malware generation (`malwaregen`), cross-site-scripting payload emission (`xss`), encoding-based bypasses (`encoding`), toxicity, and more. garak is described in the paper "garak: A Framework for Security Probing Large Language Models" (arXiv:2406.11036) and is distributed from the NVIDIA/garak GitHub repository.
13
14The scanner is generator-agnostic. It can target Hugging Face models loaded locally, OpenAI-compatible APIs, AWS Bedrock, Replicate, Cohere, NIM endpoints, GGUF/llama.cpp models, and arbitrary REST endpoints via a JSON generator spec. After a run, garak emits a `.report.jsonl` line-delimited log of every attempt and detector verdict, a human-readable `.report.html`, a `garak.log` debug log, and a hit log of confirmed vulnerabilities. The terminal output prints a per-probe, per-detector pass/fail summary with a hit rate (for example `dan.Dan_11_0 jailbreak: FAIL ok on 38/40`), which is the primary artifact you interpret.
15
16This skill maps to the MITRE ATLAS techniques **AML.T0051 (LLM Prompt Injection)** and **AML.T0054 (LLM Jailbreak)** because garak operationalizes both: it crafts prompt-injection and jailbreak inputs at scale and measures whether the target's guardrails hold. It supports the NIST AI RMF **MEASURE-2.7** subcategory by providing repeatable, quantitative security/resilience measurement of a deployed AI system.
17
18## When to Use
19
20- When you need a fast, repeatable baseline security assessment of an LLM before or after deployment.
21- When validating that a guardrail, system prompt, or safety fine-tune actually reduces jailbreak and injection success rates (run before/after and compare hit rates).
22- When producing evidence for an AI risk assessment or model card security section (NIST AI RMF MEASURE-2.7).
23- When triaging which OWASP LLM Top 10 risks (LLM01 prompt injection, LLM02 sensitive information disclosure, LLM07 system prompt leakage) actually manifest in your model.
24- When regression-testing an LLM endpoint in CI after model or prompt changes.
25
26## Prerequisites
27
28- Python 3.10+ (3.12 recommended) and a virtual environment.
29- Install garak from PyPI:
30 ```bash
31 python -m venv .venv && source .venv/bin/activate # Windows: .venv\Scripts\activate
32 python -m pip install -U garak
33 garak --version
34 ```
35- For the bleeding-edge version:
36 ```bash
37 python -m pip install -U git+https://github.com/NVIDIA/garak.git@main
38 ```
39- An API key for the target if probing a hosted model (for example `export OPENAI_API_KEY="sk-..."`).
40- Written authorization to test the target, and awareness of token cost (probes generate thousands of calls).
41
42## Objectives
43
44- Enumerate available probes and detectors and pick a scoped suite.
45- Configure garak against a local Hugging Face model, an OpenAI-compatible API, and an arbitrary REST endpoint.
46- Run prompt-injection, jailbreak, and leakage probe families and capture reports.
47- Interpret the per-probe hit-rate output and the `.report.jsonl`.
48- Re-run after applying a mitigation to demonstrate risk reduction.
49- Produce a defensible findings artifact for an AI risk assessment.
50
51## MITRE ATT&CK Mapping
52
53This skill uses MITRE ATLAS (the adversarial-ML companion to ATT&CK) technique IDs.
54
55| ID | Tactic | Official Name | Relevance |
56|----|--------|---------------|-----------|
57| AML.T0051 | ML Attack Staging / Impact | LLM Prompt Injection | garak's `promptinject` and `latentinjection` probes craft malicious prompts that subvert intended model behavior. |
58| AML.T0054 | Privilege Escalation / Defense Evasion | LLM Jailbreak | garak's `dan` and related probes attempt to bypass safety guardrails so the model produces restricted content. |
59
60## Workflow
61
62### Phase 1: Enumerate Probes and Detectors
631. List every probe garak ships so you can scope the run:
64 ```bash
65 garak --list_probes
66 ```
672. List detectors (the modules that score whether a probe succeeded) and generators (target connectors):
68 ```bash
69 garak --list_detectors
70 garak --list_generators
71 ```
723. Read the probe taxonomy. Key families:
73 - `promptinject` — PromptInject-framework direct injection.
74 - `latentinjection` — instructions hidden in documents/encoded text (indirect injection).
75 - `dan` — "Do Anything Now" and related jailbreaks (e.g. `dan.Dan_11_0`).
76 - `leakreplay` — coax the model into reproducing memorized/training or hidden-prompt text.
77 - `encoding` — base64/ROT13/etc. injection bypasses.
78 - `xss` — emit cross-site-scripting payloads (markdown/HTML exfil).
79 - `malwaregen` — request AV-evading or malicious code.
80
81### Phase 2: Probe a Local Hugging Face Model
821. Run a single jailbreak probe against a local model to validate setup:
83 ```bash
84 python -m garak --target_type huggingface --target_name gpt2 --probes dan.Dan_11_0
85 ```
862. Run a fuller suite against a chat model:
87 ```bash
88 python -m garak \
89 --target_type huggingface \
90 --target_name meta-llama/Llama-3.2-1B-Instruct \
91 --probes promptinject,dan,leakreplay \
92 --report_prefix llama32_baseline
93 ```
94
95### Phase 3: Probe an OpenAI-Compatible API
961. Export the key and run injection + leakage probes:
97 ```bash
98 export OPENAI_API_KEY="sk-..."
99 python -m garak \
100 --target_type openai \
101 --target_name gpt-4o-mini \
102 --probes promptinject,latentinjection,leakreplay \
103 --generations 5 \
104 --parallel_attempts 8 \
105 --report_prefix gpt4omini_injection
106 ```
107 - `--generations` controls how many completions per prompt (more = more statistical confidence, more cost).
108 - `--parallel_attempts` raises throughput for remote APIs.
109
110### Phase 4: Probe an Arbitrary REST Endpoint
1111. garak can target any HTTP API via a JSON generator spec. Create `rest.json`:
112 ```json
113 {
114 "rest": {
115 "RestGenerator": {
116 "name": "my-llm-gateway",
117 "uri": "https://llm.internal.example/v1/chat",
118 "method": "post",
119 "headers": { "Authorization": "Bearer $ENV_TOKEN", "Content-Type": "application/json" },
120 "req_template_json_object": { "model": "internal-bot", "prompt": "$INPUT" },
121 "response_json": true,
122 "response_json_field": "$.output"
123 }
124 }
125 }
126 ```
1272. Run garak against it:
128 ```bash
129 export ENV_TOKEN="..."
130 python -m garak \
131 --target_type rest \
132 -G rest.json \
133 --probes promptinject,dan \
134 --report_prefix internal_gateway
135 ```
136
137### Phase 5: Run a Curated Config and Full Sweep
1381. For repeatable assessments, pin everything in a YAML/JSON config and pass `--config`:
139 ```bash
140 python -m garak --config assessment.yaml
141 ```
142 ```yaml
143 # assessment.yaml
144 plugins:
145 model_type: openai
146 model_name: gpt-4o-mini
147 probe_spec: promptinject,latentinjection,dan,leakreplay,xss,malwaregen
148 run:
149 generations: 5
150 parallel_attempts: 8
151 reporting:
152 report_prefix: quarterly_llm_assessment
153 ```
1542. For an exhaustive sweep (slow, expensive) run all probes by omitting `--probes` entirely.
155
156### Phase 6: Interpret the Hit-Rate Report
1571. Read the terminal summary. Each row is `probe.Class detector: PASS|FAIL ok on N/M`. A FAIL with a low `ok` fraction means the model frequently produced the unsafe behavior — a high-severity finding.
1582. Open the machine-readable report and aggregate failures:
159 ```bash
160 # Every attempt with detector verdicts is one JSON line
161 jq -r 'select(.entry_type=="eval") | "\(.probe)\t\(.detector)\t\(.passed)/\(.total)"' \
162 garak.<timestamp>.report.jsonl | sort
163 ```
1643. Open the generated `.report.html` in a browser for the formatted scorecard and per-probe breakdown.
1654. Pull the actual successful attack strings from the hit log to use as proof-of-concept evidence.
166
167### Phase 7: Mitigate and Re-Test
1681. Apply a control (tighten the system prompt, add an input/output guardrail such as Llama Guard or LLM Guard, or change the model).
1692. Re-run the identical probe set with a new `--report_prefix`.
1703. Compare hit rates between runs to quantify risk reduction for the report.
171
172## Tools and Resources
173
174| Resource | Purpose | Link |
175|----------|---------|------|
176| NVIDIA/garak | Source, probe list, issues | https://github.com/NVIDIA/garak |
177| garak documentation | CLI reference, generator configs | https://docs.garak.ai/ and https://reference.garak.ai/ |
178| garak paper (arXiv:2406.11036) | Methodology and design | https://arxiv.org/abs/2406.11036 |
179| OWASP Top 10 for LLM Applications | Risk taxonomy probes map to | https://genai.owasp.org/ |
180| MITRE ATLAS | AML technique definitions | https://atlas.mitre.org/ |
181
182## Probe Family Reference
183
184| Probe family | Targets | OWASP LLM mapping |
185|--------------|---------|-------------------|
186| `promptinject` | Direct prompt injection | LLM01 |
187| `latentinjection` | Indirect / hidden-context injection | LLM01 |
188| `dan` | Jailbreak / guardrail bypass | LLM01 / safety |
189| `leakreplay` | Training-data & prompt leakage | LLM02 / LLM07 |
190| `encoding` | Encoding-based filter bypass | LLM01 |
191| `xss` | Markdown/HTML exfiltration payloads | LLM02 |
192| `malwaregen` | Malicious code generation | misuse |
193
194## Validation Criteria
195
196- [ ] garak installed and `garak --version` succeeds.
197- [ ] Probes and detectors enumerated with `--list_probes` / `--list_detectors`.
198- [ ] At least one probe run completed against the target with a `--report_prefix` set.
199- [ ] `.report.jsonl`, `.report.html`, and `garak.log` produced and located.
200- [ ] Per-probe hit rates extracted and ranked by severity.
201- [ ] Successful attack strings captured from the hit log as evidence.
202- [ ] A mitigation applied and a comparison re-run completed showing changed hit rates.
203- [ ] Findings documented against OWASP LLM Top 10 and MITRE ATLAS for the risk assessment.