garak-mcp-probes
Run garak against your own MCP servers.
What it is
garak-mcp-probes puts garak's existing probes through an agent that uses your own MCP servers, records every tool call the agent makes, and scores that trace with detectors for deny-listed tools, leaked canary strings, tools outside an allow-list, runaway loops and failed calls.
For servers and agents you own or are authorised to test. This repository contains no probes, no injection payloads and no jailbreak text: every prompt comes from the garak you have installed.
pip install "garak-mcp-probes @ git+https://github.com/basitalisandhu/garak-mcp-probes"
garak-mcp run --dry-run --probes test.Test --report-dir garak-mcp-report
Install
garak-mcp doctor --dry-run
garak-mcp run --dry-run --probes test.Test --report-dir garak-mcp-report
From the README; see the full README for every option.
Links
Releases
Topics: agent-security, ai-agents, ai-security, cli, detectors, docker, garak, hacktoberfest, llm-security, mcp, model-context-protocol, prompt-injection, python, red-team, sbom, security-testing, tool-use