head to head · open source
garak vs agentic_security
garak has 9,308 GitHub stars, 1,294 forks, 429 open issues and last shipped 4 days ago. agentic_security has 2,004 stars, 289 forks, 72 open issues and last shipped 9 days ago. garak leads on adoption by 364% (9,308 vs 2,004 stars). garak is written in Python under Apache-2.0; agentic_security is written in Python under Apache-2.0. garak has attracted 14% as many forks as stars, agentic_security 14%. garak was the more recently maintained of the two, and both are self-hostable with no licence fee. The two share 2 topic tags (llm-evaluation, llm-security), so they are genuine substitutes rather than adjacent tools.
Two open source projects, one decision. Both are free and self-hostable — the differences are community size, license terms, language stack and release pace.
← all 20902 open source comparisons
Side by side
| garak | agentic_security | |
|---|---|---|
| GitHub stars | ★ 9.3K | ★ 2.0K |
| License | Apache-2.0 | Apache-2.0 |
| Written in | Python | Python |
| Last push | 2026-09-16 | 2026-09-11 |
| Forks | ⑂ 1.3K | ⑂ 289 |
| Self-hosting | Yes | Yes |
| Data ownership | Your server | Your server |
pick garak if
- You weight community size — 9.3K stars and counting
- You want the Apache-2.0 license terms
- Your stack matches Python
- You value the larger contributor base for long-term maintenance
pick agentic_security if
- You want the agentic_security feature set and don't need the biggest community
- You prefer the Apache-2.0 license terms
- Your stack matches Python
- You evaluated both and agentic_security fits your workflow better
About garak
garak is a free, Apache 2.0 command line vulnerability scanner for large language models that probes generative AI systems for hallucination, data leakage, prompt injection, misinformation, toxicity generation, and jailbreaks, and it is aimed at security engineers, red teamers, and AI developers who need to test the models they ship.
read the full garak overview →
About agentic_security
Agentic Security is an open source vulnerability scanner and AI red teaming kit for agent workflows and large language models. It lives in the Python AI security ecosystem and is distributed under the Apache 2.0 license. The project addresses the problem of testing LLM applications and agent systems against jailbreaks, fuzzing, and multimodal attacks. It gives developers, researchers, and security teams a local workflow for probing model endpoints, dataset driven attack vectors, and safety thresholds before deployment.
read the full agentic_security overview →
More in AI & Machine Learning
Related comparisons
More AI Security & Privacy projects
Compare either of these against the rest of the AI Security & Privacy field.
Frequently asked questions
Is garak or agentic_security more popular?
garak has 9,308 GitHub stars and agentic_security has 2,004. garak has the larger community by that measure.
Are garak and agentic_security free?
Both are open source. garak is licensed under Apache-2.0 and agentic_security under Apache-2.0. Neither carries a licence fee.
What is the difference between garak and agentic_security?
garak is written in Python and agentic_security in Python. The practical differences are community size, licence terms, language stack and release cadence — all compared in the table above.
Which should I choose, garak or agentic_security?
Choose garak if you want the larger community (9,308 stars) or its Apache-2.0 licence terms. Choose agentic_security if its feature set, stack or Apache-2.0 licence fits better. Both are self-hostable.