Compendium Fundamentals

Fundamentals

39 lessons covering fundamentals concepts and techniques.

intermediate 10 minutes

AI Agent Threat Model: Mapping Attacks on Autonomous Systems

Learn systematic threat modeling for AI agents—understanding unique attack vectors, threat actors, and risk assessment f...

intermediate 10 minutes

AI Agents as Security Researchers: Automated Vulnerability Discovery

AI agents are becoming effective automated security researchers, capable of discovering and exploiting vulnerabilities a...

intermediate 12 minutes

AI Application Security Testing Methodology

A systematic methodology for testing AI application security that covers the shared responsibility model, attack surface...

intermediate 10 minutes

AI Security Observability and Runtime Threat Detection

Learn why AI systems require specialized observability to detect runtime attacks that bypass traditional security contro...

beginner 7 minutes

Challenge Design Principles for Security Education

Learn how effective security challenges use progressive difficulty, immediate feedback, and safe experimentation to tran...

beginner 9 minutes

Comparing AI Security Frameworks — NIST AI RMF vs Google SAIF vs OWASP Top 10

Learn how NIST AI RMF, Google SAIF, and OWASP Top 10 for LLM Applications serve different but complementary purposes in ...

intermediate 10 minutes

Comparing Automated Jailbreak Generation Paradigms

A comparative framework for understanding three automated jailbreak generation paradigms—fuzzing/mutation, sequential ch...

beginner 8 minutes

Compounding Knowledge with LLM Wikis: Why Persistent Notes Beat Ad Hoc Retrieval

Learn why persistent, interlinked wikis maintained with LLM assistance compound knowledge over time, while ad hoc retrie...

beginner 7 minutes

Contextual Modification Changes Semantic Force

A reusable fundamental showing how small wording changes can materially change how a model and judge interpret the same ...

intermediate 10 minutes

Cross-Agent Privilege Escalation: When AI Agents Free Each Other

Learn how compromise of one AI agent can cascade to others through trust relationships and shared context in multi-agent...

beginner 6 minutes

Curated Hubs Are Discovery Maps, Not Ground Truth

Learn why curated prompt-hacking resource hubs are useful watchlist expanders, but durable security lessons still need p...

beginner 8 minutes

Direct vs Indirect Prompt Injection: Where the Malicious Instruction Enters

Learn the difference between direct prompt injection and indirect prompt injection, and why modern agent security depend...

intermediate 10 minutes

Document Pipeline Security: Why Parsers Are the New Attack Surface

Learn why document pipelines that extract text from PDFs and other files create hidden attack surfaces, and how to defen...

beginner 8 minutes

Edge-Case Rule-Conforming Framing

A reusable fundamental for finding requests that appear to follow the rules while still steering the model toward a disa...

intermediate 10 minutes

Enterprise AI Agent Security: The Four-Pillar Framework

Learn the four-pillar framework for securing AI agents in enterprise environments—visibility, governance, risk assessmen...

intermediate 10 minutes

Enterprise Integration Security for AI Platforms

Learn how to secure AI systems integrated into enterprise platforms through shared responsibility models, platform-speci...

beginner 7 minutes

Evaluating Sources — A Methodology for Trust and Quality

Learn a practical four-tier framework for evaluating prompt-hacking research sources by trust level, evidence quality, a...

beginner 7 minutes

Excessive Agency: Why Unconstrained Capabilities Create Attack Surface

Learn why AI agents with unnecessary capabilities create excessive attack surface, and how the principle of least privil...

beginner 8 minutes

Why External Content Is the Real Attack Surface for Agents

Learn why modern AI agents face expanded security risks from external content—files, web pages, and emails—and how parse...

beginner 8 minutes

The First Try Fallacy: Why Persistence Beats Probability

Learn why LLM security testing requires multiple attempts. The 'First Try Fallacy' causes attackers to abandon...

beginner 8 minutes

Helpfulness Exploitation Through Legitimate-Seeming Preferences

A reusable fundamental showing how assistants can be manipulated by requests that look like ordinary personalization or ...

beginner 6 minutes

Learning by Hacking: Interactive AI Security Education

Interactive challenges teach AI security more effectively than passive reading because they create experiential understa...

intermediate 10 minutes

Jailbreak Research: Methodology and Ethics

Learn responsible jailbreak research methodology that balances discovery with safety through structured boundaries, docu...

beginner 8 minutes

Mapping AI Attacks with MITRE ATLAS: A Practical Guide

Learn how to use MITRE ATLAS to map AI attacks as systematic adversary chains rather than isolated tricks, enabling bett...

beginner 8 minutes

Misinformation: When Models Generate False Content

Learn why LLM misinformation is a security risk and how to build verification controls that prevent harmful decisions ba...

beginner 10 minutes

Navigating Challenge Families: A Systematic Approach

Learn how to approach challenge families systematically through observation, experimentation, failure analysis, and prog...

beginner 10 minutes

NIST AI RMF: The Four Functions of AI Risk Management

Learn NIST's four-function framework for continuous AI risk management — Govern, Map, Measure, and Manage — and how...

beginner 6 minutes

PDF Hidden Instruction Detection Basics

Learn simple, effective techniques to detect hidden instructions in PDF documents before they reach AI processing pipeli...

beginner 6 minutes

The Business Impact of PDF Prompt Injection

How invisible instructions in PDF documents can manipulate LLM-driven business workflows and alter automated financial d...

beginner 6 minutes

Prompt Injection Is Initial Access, Not the Whole Attack

Learn why prompt injection is often the entry point to a larger AI attack chain, not the entire incident by itself.

Lab: DAN
beginner 6 minutes

Prompt Injection in Context: Understanding the OWASP #1 LLM Risk

Learn why prompt injection ranks as the

intermediate 8 minutes

Prompt Injection as Social Engineering: How Agents Get Manipulated in Context

Learn why modern prompt injection increasingly behaves like social engineering inside normal-looking workflows, where be...

beginner 7 minutes

The SAIF Framework — Four Pillars of AI Security

Learn how Google's Secure AI Framework structures AI security through four expandable pillars that extend tradition...

beginner 7 minutes

The Shared Responsibility Model for AI Security

AI application security follows a shared responsibility model where model providers, application developers, and infrast...

intermediate 8 minutes

Source-Sink Thinking: Where Agent Prompt Injection Becomes Dangerous

Learn how to reason about agent prompt-injection risk by tracking whether untrusted input can reach a sensitive sink lik...

intermediate 10 minutes

Supply Chain Vulnerabilities in LLM Applications

Learn how LLM supply chains extend beyond traditional software dependencies to include models, data, and deployment plat...

beginner 6 minutes

System Prompts Are Control Surfaces, Not Containment

Learn why system prompts guide behavior but should not be treated as reliable security boundaries on their own.

beginner 8 minutes

Unbounded Consumption: Resource Limits and Availability Protection

Learn how unbounded consumption creates security risks through resource exhaustion, denial of service, and unexpected co...

beginner 10 minutes

Understanding the Bot-Tricks Technique Taxonomy: A Guide to the Arcanum Classification System

Learn how the Arcanum taxonomy organizes 107 prompt injection patterns across four dimensions (intents, techniques, evas...