Learn AI security by breaking it. Lessons, techniques, and hands-on labs built from real-world prompt injection incidents. Free, browser-based, safe.
Curated sequences of labs and lessons that take you from beginner to practitioner.
Hide prompt injection inside images a code-review agent will read — then find the secret in what it posts. Metadata channels, refusal bypass, redaction override, chunked exfiltration.
How AI vulnerabilities open old web bug classes like XSS and SSRF. Two custom labs, five core lessons.
Foundational techniques every AI red teamer needs. Start here if you're new to prompt injection.
The art of poisoning data sources to compromise AI systems. RAG exploits, calendar poisoning, agentic workflows.
Actual incidents, recreated as hands-on training. Account takeover, price override, data exfiltration.
Build better AI defenses. Input sanitization, output filtering, confirmation gates, and monitoring — grounded in real attack patterns.
Explore the compendium by subject area.
Every lesson links to a hands-on lab where you can practice the technique safely.
GitHub Agentic Workflows prompt injection. Leak private repo data through a poisoned issue.
Calendar poisoning. Trick a calendar AI into leaking a private Executive Calendar.
Slack AI data exfiltration. Hide injection in meeting transcripts to leak private channels.