// Tools

10 open-source tools across all OWASP LLM categories

Tools for calculating, monitoring, and capping LLM API costs to defend against unbounded consumption attacks.
Stanford's Holistic Evaluation of Language Models combined with TruthfulQA for measuring factual accuracy and truthfulness.
Open-source tool for managing, auditing, and securing vector database contents used in RAG pipelines.
A red-team tool for automated discovery and extraction of system prompts from LLM-powered applications.
A comprehensive benchmark for evaluating LLM agents across diverse real-world tasks, including security-relevant scenarios.
LLM05LLM02Defenseactive
Real-time LLM output scanning library that detects and blocks malicious content, PII, prompt injection in responses, and toxic outputs.
Open-source library for finding and fixing label errors, outliers, and near-duplicates in training datasets — essential for poisoning prevention.
Protect-AI's open-source scanner that detects malicious code in ML model files before they are loaded into memory.
LLM02LLM05Defenseactive
A defense-in-depth combination: Presidio for PII detection/anonymization and LLM Guard for real-time LLM input/output scanning.
LLM01LLM02LLM07Red Teamactive
An open-source LLM vulnerability scanner that probes models for prompt injection, jailbreaks, and dozens of other failure modes.