Suggestions appear as you type. Use the up and down arrows to choose one and Enter to open it.

This page's audience real numbers from our own analytics — open to see them
–Visitors
–Page views
–Clicks to vendors
–Time on page
–Reading now
Clicks to vendors, by tool
  • –
Top countries
  • –
Devices
  • –

– · counted by iTechGuides's own first-party analytics, bots removed, every figure rounded down · how we count

Basilisk

Free#13 of 29 in AI Security Testing Tools

Basilisk: Broad self-hosted AI security testing with evolutionary adversarial search and CI/CD support. Ranked #13 of 29 in AI Security Testing Tools by our editors (7.9/10); pricing: Free plan; best for open-source teams needing broad local testing.

7.9/10Editor score
Basilisk7.9 Visit Basilisk

At a glance

  • Editor score
    7.9 / 10
  • Pricing
    Free plan
  • Best for
    Open-source teams needing broad local testing
  • Free plan
    Yes
  • Paid from
    None
  • Prompt injection tests
    Yes
  • Facts checked
    21 Sep 2026
Basilisk screenshot
  • Where it wins

    • Evolutionary prompt search covers injection, jailbreak, RAG, and leakage attacks
    • Works across Windows, macOS, Linux, hosted models, and local runtimes
    • Exports HTML, JSON, SARIF, Markdown, and PDF reports for security workflows
  • Where it doesn't

    • Self-hosted deployment requires teams to manage the operating environment
    • AGPL-3.0 licensing may require review before commercial adoption
    • Its broad module set may require security expertise to configure and interpret

Our verdict on Basilisk

Basilisk is an open-source AI red teaming and LLM security testing framework for security researchers, penetration testers, and defensive teams. It runs on Windows, macOS, and Linux, and supports hosted and local language models through integrations including OpenAI, Anthropic, Google Gemini, Azure, AWS Bedrock, Ollama, vLLM, and llama.cpp. Its self-hosted model suits teams that want local control over testing workflows and evidence.

Its standout capability is evolutionary adversarial prompt search, which automates the discovery of challenging prompts instead of limiting assessments to fixed examples. The testing scope includes OWASP-aligned attack modules, prompt injection, jailbreaks, data exfiltration, RAG attacks, unsafe outputs, and guardrail posture. Differential scanning can compare multiple models, while deterministic evaluation suites with assertions support repeatable checks and custom test cases. These capabilities make Basilisk a fit for teams building structured security evaluations across changing models and deployments.

Basilisk also fits development and audit workflows through GitHub Actions CI/CD integration, signed audit logging, evidence-backed findings, and exports in HTML, JSON, SARIF, Markdown, and PDF. The breadth is useful for open-source teams that need one framework spanning local runtimes, model APIs, attack testing, reporting, and regression checks. However, self-hosting shifts environment management and operational responsibility to the adopting team, and the AGPL-3.0 license may not suit every commercial distribution model. Choose Basilisk for broad, locally controlled testing; consider a different tool if you need a managed service or a narrower workflow with less operational ownership.

Basilisk pricing

Plans Free planFree Free to use — no paid tier required for the core job.
See plans on basilisk.rothackers.com

Basilisk fact sheet

Free planYes
Paid fromNone
Prompt injection testsYes
Jailbreak testsYes
Data leakage testsYes
Unsafe output testsYes
Custom test casesYes
Deployment modeSelf_hosted
DeploymentSelf-hosted, Desktop
PlatformsWindows, macOS, Linux
SupportEmail
Built forSmall business, Mid-market, Enterprise (editorial estimate)
Integrations12 integrations: OpenAI, Anthropic, Google Gemini, NVIDIA API Catalog, xAI Grok, Groq …
PricingFree plan
Websitebasilisk.rothackers.com
Facts checked21 Sep 2026

Basilisk integrations

Basilisk lists 12 integrations on its own site.

  • OpenAI
  • Anthropic
  • Google Gemini
  • NVIDIA API Catalog
  • xAI Grok
  • Groq
  • Azure
  • AWS Bedrock
  • GitHub Models
  • Ollama
  • vLLM
  • llama.cpp

Alternatives to Basilisk

See all Basilisk alternatives →

Used Basilisk? Be the first to review it

The editor score above is our own research. What this page doesn't have yet is a reader's view — what you used Basilisk for, what worked and what didn't. No stars are seeded and no review is paid for; an editor reads every one before it appears.

Write a reviewTwo minutes · verified accounts only · read by an editor before it appears

Reviews come only from verified accounts. Sign in or create an account first — your e-mail is never shown.

Your rating

0 characters · at least 80, up to 3,000

Posted from your verified account. Reviews appear after an editor reads them, usually within two working days.

Featured on iTechGuides

Featured on iTechGuides — Basilisk 7.9/10

Basilisk is listed in our AI Security Testing Tools directory. Add the badge to your site — it links back to this page.

<a href="https://www.itechguides.com/products/basilisk-ai-security-testing-tool/"><img src="https://www.itechguides.com/best/badge/basilisk-ai-security-testing-tool.svg" alt="Featured on iTechGuides" width="230" height="46"></a>

Guides on AI security testing tools

Reviewed by iTechGuides Editors · Editorial team · Updated Oct 2026

Advertiser disclosure: iTechGuides is reader-supported. We may earn a commission when you click some links. How we rank.

Last updated · How we research and update