China AI Compliance Audit
jnMetaCode/shellward
按中国法规(网安法 / PIPL / 等保2.0 / 数据出境 / AI生成内容标识)审计一个 AI 项目的代码仓库,产出每条都带 文件:行 取证、经独立复核、经脚本校验的合规报告。当用户问「这个项目上线合不合规」「调用了 OpenAI/Claude 算不算数据出境」「要不要做 AI 标识」「帮我做合规自查/等保/PIPL 检查」时使用。Audit an AI project's…
Runs NVIDIA garak probe suites (jailbreak, prompt injection, data leakage, toxicity, and more) against an LLM endpoint - Hugging Face models, OpenAI-compatible APIs, or Bedrock - then interprets the…
The automated check flagged lines worth reading first. See the safety section below.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill red-teaming-llms-with-garak -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills red-teaming-llms-with-garak --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/red-teaming-llms-with-garak .claude/skills/red-teaming-llms-with-garak && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "red-teaming-llms-with-garak" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/red-teaming-llms-with-garak into .claude/skills/red-teaming-llms-with-garak/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "red-teaming-llms-with-garak", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/red-teaming-llms-with-garakType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill red-teaming-llms-with-garak -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills red-teaming-llms-with-garak --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/red-teaming-llms-with-garak .agents/skills/red-teaming-llms-with-garak && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "red-teaming-llms-with-garak" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/red-teaming-llms-with-garak into .agents/skills/red-teaming-llms-with-garak/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "red-teaming-llms-with-garak", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill red-teaming-llms-with-garak -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills red-teaming-llms-with-garak --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/red-teaming-llms-with-garak .cursor/skills/red-teaming-llms-with-garak && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "red-teaming-llms-with-garak" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/red-teaming-llms-with-garak into .cursor/skills/red-teaming-llms-with-garak/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "red-teaming-llms-with-garak", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git --path skills/red-teaming-llms-with-garak--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill red-teaming-llms-with-garak -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills red-teaming-llms-with-garak --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/red-teaming-llms-with-garak .gemini/skills/red-teaming-llms-with-garak && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "red-teaming-llms-with-garak" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/red-teaming-llms-with-garak into .gemini/skills/red-teaming-llms-with-garak/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "red-teaming-llms-with-garak", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills red-teaming-llms-with-garakInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill red-teaming-llms-with-garak -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/red-teaming-llms-with-garak .github/skills/red-teaming-llms-with-garak && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "red-teaming-llms-with-garak" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/red-teaming-llms-with-garak into .github/skills/red-teaming-llms-with-garak/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "red-teaming-llms-with-garak", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill red-teaming-llms-with-garak -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills red-teaming-llms-with-garak --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/red-teaming-llms-with-garak .opencode/skills/red-teaming-llms-with-garak && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "red-teaming-llms-with-garak" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/red-teaming-llms-with-garak into .opencode/skills/red-teaming-llms-with-garak/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "red-teaming-llms-with-garak", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
red-teaming-llms-with-garakRuns NVIDIA garak probe suites (jailbreak, prompt injection, data leakage, toxicity, and more) against an LLM endpoint - Hugging Face models, OpenAI-compatible APIs, or Bedrock - then interprets the…
Red Teaming LLMs With Garak is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Runs NVIDIA garak probe suites (jailbreak, prompt injection, data leakage, toxicity, and more) against an LLM endpoint - Hugging Face models, OpenAI-compatible APIs, or Bedrock - then interprets the resulting hit-rate report for triage. Use when baselining LLM security before/after deployment, validating that a guardrail or fine-tune reduces jailbreak/injection success rates, or producing evidence for an AI risk assessment.
Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts and reference files (for example `references/api-reference.md`, `references/standards.md` and `scripts/agent.py`).
It sits in Security, covering Prompt injection and agent security, Red teaming and adversary simulation and LLM guardrails. It works with Hugging Face, OpenAI and NVIDIA AI Platform. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
pythonjqFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
github.comAlso links to:
docs.garak.aireference.garak.aiarxiv.orggenai.owasp.orgatlas.mitre.orgFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
OPENAI_API_KEYENV_TOKENFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Red Teaming LLMs With Garak loads about 2.9k tokens when it runs, and up to ~4k if it reads all its reference files. Until then it costs about 114 tokens; SKILL.md has 1,103 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found patterns that need a careful read before installing.
k's `dan` and related probes attempt to bypass safety guardrails so the model produces restricted content. |Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 1,103 words, ~2,872 tokens.
.claude/skills/red-teaming-llms-with-garak/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.Legal and Authorized-Use Notice: This skill is for authorized AI security testing and educational purposes only. Probe only models, API keys, and endpoints you own or have explicit written permission to test. Automated probing of third-party LLM APIs may violate their terms of service and consume billable tokens. Unauthorized probing of systems you do not control may be illegal.
garak (Generative AI Red-teaming and Assessment Kit) is an open-source LLM vulnerability scanner maintained by NVIDIA. It plays the role that a network vulnerability scanner like Nessus plays for hosts, but for large language models: it sends thousands of adversarial prompts ("probes") at a target model, captures the generations, and runs automated "detectors" over the responses to decide whether each attempt succeeded. Probe families cover prompt injection (promptinject, latentinjection), jailbreaks (dan), training-data and system-prompt leakage (leakreplay), malware generation (malwaregen), cross-site-scripting payload emission (xss), encoding-based bypasses (encoding), toxicity, and more. garak is described in the paper "garak: A Framework for Security Probing Large Language Models" (arXiv:2406.11036) and is distributed from the NVIDIA/garak GitHub repository.
The scanner is generator-agnostic. It can target Hugging Face models loaded locally, OpenAI-compatible APIs, AWS Bedrock, Replicate, Cohere, NIM endpoints, GGUF/llama.cpp models, and arbitrary REST endpoints via a JSON generator spec. After a run, garak emits a .report.jsonl line-delimited log of every attempt and detector verdict, a human-readable .report.html, a garak.log debug log, and a hit log of confirmed vulnerabilities. The terminal output prints a per-probe, per-detector pass/fail summary with a hit rate (for example dan.Dan_11_0 jailbreak: FAIL ok on 38/40), which is the primary artifact you interpret.
This skill maps to the MITRE ATLAS techniques AML.T0051 (LLM Prompt Injection) and AML.T0054 (LLM Jailbreak) because garak operationalizes both: it crafts prompt-injection and jailbreak inputs at scale and measures whether the target's guardrails hold. It supports the NIST AI RMF MEASURE-2.7 subcategory by providing repeatable, quantitative security/resilience measurement of a deployed AI system.
python -m venv .venv && source .venv/bin/activate # Windows: .venv\Scripts\activate
python -m pip install -U garak
garak --versionpython -m pip install -U git+https://github.com/NVIDIA/garak.git@mainexport OPENAI_API_KEY="sk-...")..report.jsonl.This skill uses MITRE ATLAS (the adversarial-ML companion to ATT&CK) technique IDs.
| ID | Tactic | Official Name | Relevance |
|---|---|---|---|
| AML.T0051 | ML Attack Staging / Impact | LLM Prompt Injection | garak's promptinject and latentinjection probes craft malicious prompts that subvert intended model behavior. |
| AML.T0054 | Privilege Escalation / Defense Evasion | LLM Jailbreak | garak's dan and related probes attempt to bypass safety guardrails so the model produces restricted content. |
garak --list_probesgarak --list_detectors
garak --list_generatorspromptinject — PromptInject-framework direct injection.latentinjection — instructions hidden in documents/encoded text (indirect injection).dan — "Do Anything Now" and related jailbreaks (e.g. dan.Dan_11_0).leakreplay — coax the model into reproducing memorized/training or hidden-prompt text.encoding — base64/ROT13/etc. injection bypasses.xss — emit cross-site-scripting payloads (markdown/HTML exfil).malwaregen — request AV-evading or malicious code.python -m garak --target_type huggingface --target_name gpt2 --probes dan.Dan_11_0python -m garak \
--target_type huggingface \
--target_name meta-llama/Llama-3.2-1B-Instruct \
--probes promptinject,dan,leakreplay \
--report_prefix llama32_baselineexport OPENAI_API_KEY="sk-..."
python -m garak \
--target_type openai \
--target_name gpt-4o-mini \
--probes promptinject,latentinjection,leakreplay \
--generations 5 \
--parallel_attempts 8 \
--report_prefix gpt4omini_injection--generations controls how many completions per prompt (more = more statistical confidence, more cost).--parallel_attempts raises throughput for remote APIs.rest.json:{
"rest": {
"RestGenerator": {
"name": "my-llm-gateway",
"uri": "https://llm.internal.example/v1/chat",
"method": "post",
"headers": { "Authorization": "Bearer $ENV_TOKEN", "Content-Type": "application/json" },
"req_template_json_object": { "model": "internal-bot", "prompt": "$INPUT" },
"response_json": true,
"response_json_field": "$.output"
}
}
}export ENV_TOKEN="..."
python -m garak \
--target_type rest \
-G rest.json \
--probes promptinject,dan \
--report_prefix internal_gateway--config:python -m garak --config assessment.yaml# assessment.yaml
plugins:
model_type: openai
model_name: gpt-4o-mini
probe_spec: promptinject,latentinjection,dan,leakreplay,xss,malwaregen
run:
generations: 5
parallel_attempts: 8
reporting:
report_prefix: quarterly_llm_assessment--probes entirely.probe.Class detector: PASS|FAIL ok on N/M. A FAIL with a low ok fraction means the model frequently produced the unsafe behavior — a high-severity finding.# Every attempt with detector verdicts is one JSON line
jq -r 'select(.entry_type=="eval") | "\(.probe)\t\(.detector)\t\(.passed)/\(.total)"' \
garak.<timestamp>.report.jsonl | sort.report.html in a browser for the formatted scorecard and per-probe breakdown.--report_prefix.| Resource | Purpose | Link |
|---|---|---|
| NVIDIA/garak | Source, probe list, issues | https://github.com/NVIDIA/garak |
| garak documentation | CLI reference, generator configs | https://docs.garak.ai/ and https://reference.garak.ai/ |
| garak paper (arXiv:2406.11036) | Methodology and design | https://arxiv.org/abs/2406.11036 |
| OWASP Top 10 for LLM Applications | Risk taxonomy probes map to | https://genai.owasp.org/ |
| MITRE ATLAS | AML technique definitions | https://atlas.mitre.org/ |
| Probe family | Targets | OWASP LLM mapping |
|---|---|---|
promptinject | Direct prompt injection | LLM01 |
latentinjection | Indirect / hidden-context injection | LLM01 |
dan | Jailbreak / guardrail bypass | LLM01 / safety |
leakreplay | Training-data & prompt leakage | LLM02 / LLM07 |
encoding | Encoding-based filter bypass | LLM01 |
xss | Markdown/HTML exfiltration payloads | LLM02 |
malwaregen | Malicious code generation | misuse |
garak --version succeeds.--list_probes / --list_detectors.--report_prefix set..report.jsonl, .report.html, and garak.log produced and located.© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (scripts, references) in skills/red-teaming-llms-with-garak of mukul975/Anthropic-Cybersecurity-Skills.
Open the folder on GitHubat commit 54a7988
Red Teaming LLMs With Garak next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Red Teaming LLMs With Garak this skillmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2.9k | Automated safety check: Warn | Apache-2.0 | |
| China AI Compliance AuditjnMetaCode/shellward | 140 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | |
| LlamaGuard Content ModerationOrchestra-Research/AI-Research-SKILLs | 13k | 2 repos | ~2.3k | Automated safety check: Pass | MIT | |
| Dataset Transformationawslabs/agent-plugins | 916 | 1 repos | ~3.5k | Automated safety check: Pass | Apache-2.0 | |
| 9Router Speech-to-Textdecolua/9router | 31k | — | ~914 | Automated safety check: Pass | MIT | |
| Writing Eval Scenariosopen-bias/open-bias | 143 | — | ~1.5k | Automated safety check: Pass | Apache-2.0 |
jnMetaCode/shellward
按中国法规(网安法 / PIPL / 等保2.0 / 数据出境 / AI生成内容标识)审计一个 AI 项目的代码仓库,产出每条都带 文件:行 取证、经独立复核、经脚本校验的合规报告。当用户问「这个项目上线合不合规」「调用了 OpenAI/Claude 算不算数据出境」「要不要做 AI 标识」「帮我做合规自查/等保/PIPL 检查」时使用。Audit an AI project's…
Orchestra-Research/AI-Research-SKILLs
Uses Meta's LlamaGuard moderation model to screen prompts and model replies against six safety categories, with vLLM, FastAPI and NeMo Guardrails setups.
awslabs/agent-plugins
Generates code that transforms datasets between ML schemas for model training or evaluation.
decolua/9router
Transcribes audio files into text or subtitles through 9Router's Whisper-compatible endpoint, using models from OpenAI, Groq, Gemini, Deepgram and others.
open-bias/open-bias
Guide for writing eval conversation JSONs and running them through policy engines
letta-ai/skills
Fetch and summarize recent AI news from curated RSS feeds (Hugging Face, VentureBeat, The Verge, OpenAI, Anthropic, DeepMind, etc.) and YouTube channels (Yannic Kilcher, Two Minute Papers, AI…
mukul975/Anthropic-Cybersecurity-Skills
Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.
mukul975/Anthropic-Cybersecurity-Skills
Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.
mukul975/Anthropic-Cybersecurity-Skills
Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.
mukul975/Anthropic-Cybersecurity-Skills
Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.
mukul975/Anthropic-Cybersecurity-Skills
Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.
mukul975/Anthropic-Cybersecurity-Skills
Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.
Works with
Categories
Runs NVIDIA garak probe suites (jailbreak, prompt injection, data leakage, toxicity, and more) against an LLM endpoint - Hugging Face models, OpenAI-compatible APIs, or Bedrock - then interprets the…. Red Teaming LLMs With Garak is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Runs NVIDIA garak probe suites (jailbreak, prompt injection, data leakage, toxicity, and more) against an LLM endpoint - Hugging Face models, OpenAI-compatible APIs, or Bedrock - then interprets the resulting hit-rate report for triage.
Red Teaming LLMs With Garak fits situations like: baselining LLM security before/after deployment; validating that a guardrail; fine-tune reduces jailbreak/injection success rates; producing evidence for an AI risk assessment.
Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill red-teaming-llms-with-garak -a claude-code`. Or copy the skill folder (skills/red-teaming-llms-with-garak in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/red-teaming-llms-with-garak in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill red-teaming-llms-with-garak -a codex`. Or copy the skill folder (skills/red-teaming-llms-with-garak in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/red-teaming-llms-with-garak in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill red-teaming-llms-with-garak -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/red-teaming-llms-with-garak, .gemini/skills/red-teaming-llms-with-garak, .github/skills/red-teaming-llms-with-garak and .opencode/skills/red-teaming-llms-with-garak in your project.
Going by SKILL.md and its folder, Red Teaming LLMs With Garak needs Python for the scripts in its folder, the command-line tools its instructions call (python and jq) and credentials named OPENAI_API_KEY and ENV_TOKEN. Our summary lists: Python 3; A credential in OPENAI_API_KEY; A credential in ENV_TOKEN.
SKILL.md names 6 domains. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. As links in the text: docs.garak.ai, reference.garak.ai, arxiv.org, genai.owasp.org and atlas.mitre.org. This is read from the text; nothing was executed.
Our automated static check of SKILL.md flagged 1 warning(s): contains instruction-override wording (e.g. “without asking the user”). Read the flagged lines before installing; the check is not a guarantee either way. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Red Teaming LLMs With Garak is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.9k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.1k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Red Teaming LLMs With Garak: China AI Compliance Audit (jnMetaCode/shellward, 140 stars), LlamaGuard Content Moderation (Orchestra-Research/AI-Research-SKILLs, 13k stars), Dataset Transformation (awslabs/agent-plugins, 916 stars) and 9Router Speech-to-Text (decolua/9router, 31k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.
Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.