Compare
Bernstein vs Garak: quick decision guide
Garak adversarial probe adapter.
Page built on 2026-09-18 from data/adapters-meta.json. Every claim below links to its primary source.
Install both
Garak
pip install garakBernstein
pipx install bernsteinApache-2.0. Deterministic Python scheduler.
Feature matrix
| Capability | Garak | Bernstein |
|---|---|---|
| Install method | pip install garak | pipx install bernstein |
| License | Not recorded | Apache-2.0 |
| Authentication | Not recorded | Per-agent credential scoping (no shared key) |
| Multi-agent orchestration | One agent in a terminal | Garak plus 40+ other adapters in parallel worktrees |
| MCP support | Not measured | Yes |
| Parallel-safe in worktrees | Not measured | Yes (designed around git worktrees) |
| HMAC-chained audit log | No | Yes (RFC 2104 SHA-256 chain in .sdd/) |
| Deterministic scheduler | Not applicable (single-agent CLI) | Yes (Deterministic Python scheduler) |
Adapter source: src/bernstein/adapters/garak.py | Upstream repo: NVIDIA/garak
Verifiable facts
The brief for this surface requires at least three facts that a reader can verify against a primary source. The list below is built from the bernstein adapter source and, when available, the upstream project's own pages.
- Bernstein ships a Garak adapter at src/bernstein/adapters/garak.py that wraps the upstream CLI as one of 42 routable agents. [source: bernstein adapter source, as of 2026-09-18]
- Upstream install command, as recorded in the bernstein adapter, is "pip install garak". [source: upstream repo, as of 2026-09-18]
- Bernstein is an open-source Multi-agent orchestrator licensed Apache-2.0, with a deterministic Python scheduler that routes work across CLI agents in parallel git worktrees. [source: bernstein repo, as of 2026-09-18]
Where Garak fits in Bernstein
Bernstein registers Garak under the slug "garak" and the registry name "garak". The adapter source lives at src/bernstein/adapters/garak.py in the bernstein repo and was last touched at build time 2026-09-18. The Garak adapter file is 338 lines and 13,041 bytes long, fingerprinted dc68e6f6e28f531d (first 16 hex chars of SHA-256). Operators install Garak on a worker box with "pip install garak" before Bernstein routes any task to it. Upstream code lives at github.com/NVIDIA/garak, the canonical source operators audit when verifying the bernstein adapter against upstream behaviour. The bernstein adapter file for Garak does not yet carry a "Last verified against upstream" line; this means the adapter still tracks an unpinned upstream binary. Bernstein routes tasks to Garak when its pass rate on similar work clears the configured threshold, otherwise the deterministic Python scheduler picks a different adapter from the 40+ adapter catalog.
Adapter source excerpt
The module docstring of the Garak adapter, as it stands in the bernstein repo. Punctuation is normalised for the web; the wording is the author's. Length: 224 characters.
Garak adversarial probe adapter. Spawns garak CLI, parses its JSONL attempt log, and produces a CampaignArtifact report binding: tool version, probe set, target descriptor, invocation argv hash, and attempt-log content hash.Adapter telemetry
| Registry name | garak |
|---|---|
| Adapter class | Garak |
| Source file | src/bernstein/adapters/garak.py |
| Source file size | 338 lines, 13,041 bytes |
| Source SHA-256 | dc68e6f6e28f531dd72adda63e202ec74cc5067b32dd99237d6cd5cccbaeb3cd |
| Category bucket | cli-family |
| Upstream repo | NVIDIA/garak |
| Upstream homepage | Not recorded |
| Last verified upstream | No "Last verified" line in adapter source |
| Operator-curated overlay | No (programmatic page) |
When to pick which
Choose Garak
Reach for Garak when the work is a single thread that fits one agent: in a single-process terminal session, designed for single-instance use per repo. Auth model is configured per upstream docs. You skip the orchestrator round-trip and get the smallest possible surface between you and the model.
Choose Bernstein
Wrap Garak under Bernstein when the goal splits into parallel tasks, when you want an HMAC-chained audit log on every routing decision, or when a deterministic Python scheduler (no LLM picking who runs what) is a hard requirement.
FAQ
Does Bernstein replace Garak?
No. Bernstein wraps Garak as one of 40+ CLI adapters and routes tasks to it based on per-task pass-rate history. Garak keeps running unchanged; Bernstein decides when it gets work.
Can I run Garak alongside other agents in the same repo?
Yes. Each agent runs in its own git worktree under .sdd/worktrees/{session_id}, so file edits never collide. Bernstein merges results back to the trunk only after the configured quality gates (lint, types, tests) pass.
Is this comparison page handwritten?
No. The template is fixed; every fact and every link is pulled from the bernstein adapter source in the master branch and (when available) the upstream project's own pages. The data extractor lives at scripts/gen-compare-data.mjs. No LLM writes the prose.