Home / MCP tooling

garak-mcp-probes

Run garak against your own MCP servers.

Python · MIT · latest v0.1.0

What it is

garak-mcp-probes puts garak's existing probes through an agent that uses your own MCP servers, records every tool call the agent makes, and scores that trace with detectors for deny-listed tools, leaked canary strings, tools outside an allow-list, runaway loops and failed calls.

For servers and agents you own or are authorised to test. This repository contains no probes, no injection payloads and no jailbreak text: every prompt comes from the garak you have installed.

pip install "garak-mcp-probes @ git+https://github.com/basitalisandhu/garak-mcp-probes"
garak-mcp run --dry-run --probes test.Test --report-dir garak-mcp-report

Install

garak-mcp doctor --dry-run
garak-mcp run --dry-run --probes test.Test --report-dir garak-mcp-report

From the README; see the full README for every option.

Releases

Topics: agent-security, ai-agents, ai-security, cli, detectors, docker, garak, hacktoberfest, llm-security, mcp, model-context-protocol, prompt-injection, python, red-team, sbom, security-testing, tool-use