AI & LLM Security
Training
Train employees to spot prompt injection, deepfakes, and AI-generated phishing before attackers exploit your AI tools.
43 interactive exercises across AI at Work and the OWASP Top 10 for LLM, agentic and MCP applications. Free to play, no sign-up required.
AI at Work
13 exercises
AI-Written Phishing
Spot a phishing email with perfect spelling and your project name.
- ATT&CKT1566.002
- CIS 14.2
AI Voice Phishing Calls
Take a scam call from an AI that answers every question.
- ATT&CKT1566.004
- EU AI ActArt. 50
- CIS 14.2
Cloned Voice Payment Fraud
Handle a payment request sent as your manager's voice note.
- ATT&CKT1656
- EU AI ActArt. 50
- CIS 14.2
Voice Clone Impersonation
Handle the fallout when a clone of your voice calls a colleague.
- ATT&CKT1656
- EU AI ActArt. 50
- CIS 14.2
Deepfake Hiring Fraud
Run a liveness check on a remote candidate mid-interview.
- ATT&CKT1656
- EU AI ActArt. 50
- CIS 14.2
- NIST CSFPR.AA
AI Support Chatbot Scam
Spot a fake AI support chat that asks for your login code.
- ATT&CKT1566.002
- EU AI ActArt. 50
- CIS 14.2
Unapproved AI Notetakers
Find the AI notetaker sitting in a confidential HR meeting.
- GDPRArt. 5
- EU AI ActArt. 4
- CIS 3
- NIST CSFPR.DS
Prompt Injection in Documents
Trace an AI summary back to hidden text inside a PDF.
- OWASP LLMLLM01:2026
- CWE-1427
- ATT&CKT1566.001
- EU AI ActArt. 4
- CIS 14.2
Unreviewed AI Output
Cut the internal details out of an AI-drafted client reply.
- OWASP LLMLLM02:2026
- GDPRArt. 5
- EU AI ActArt. 4
- CIS 14.4
Shadow AI Tools
Photograph a roadmap into a free AI app, then put it right.
- GDPRArt. 5
- EU AI ActArt. 4
- CIS 14.4
- NIST CSFID.AM
AI Agent Payment Fraud
Watch a web page redirect the payment your AI agent makes.
- OWASP LLMLLM01:2026
- CWE-1427
- ATT&CKT1657
- EU AI ActArt. 4
- CIS 14.2
AI Assistant Oversharing
Check the source when an assistant answers with colleagues' salaries.
- OWASP LLMLLM02:2026
- GDPRArt. 5
- EU AI ActArt. 4
- CIS 14.4
- NIST CSFPR.DS
Shared AI Agent Access
Share an assistant built on your files and watch it answer with your access.
- OWASP LLMLLM02:2026
- GDPRArt. 5
- EU AI ActArt. 4
- CIS 14.4
- NIST CSFPR.AA
OWASP Top 10 for LLM Applications
10 exercises
Clawdbot (Moltbot) Prompt Injection
Stop a hidden prompt from hijacking your AI assistant mid-task.
- OWASP LLMLLM01:2026
- CWE-1427
- CIS 16
- NIST CSFPR.PS
Sensitive Data Exposure Through AI
See what happens when confidential data enters a consumer AI tool.
- OWASP LLMLLM02:2026
- CWE-200
- CIS 16
- NIST CSFPR.PS
AI Supply Chain Attack
Deploy an AI plugin that hides a backdoor in plain sight.
- OWASP LLMLLM04:2026
- CWE-1104
- CIS 16
- NIST CSFPR.PS
AI Knowledge Base Poisoning
Watch poisoned documents corrupt your AI's answers in real time.
- OWASP LLMLLM05:2026
- CIS 16
- NIST CSFPR.PS
Unsafe AI Output Handling
Exploit an AI whose outputs flow unchecked into live systems.
- OWASP LLMLLM10:2026
- CWE-1426
- CIS 16
- NIST CSFPR.PS
Over-Permissioned AI Agent
Manipulate an AI assistant into misusing its own permissions.
- OWASP LLMLLM03:2026
- CWE-250
- CIS 16
- NIST CSFPR.PS
AI System Prompt Leakage
Extract hidden instructions from a customer-facing AI chatbot.
- OWASP LLMLLM08:2026
- CWE-200
- CIS 16
- NIST CSFPR.PS
RAG Pipeline Exploitation
Exploit a RAG pipeline to access documents beyond your clearance.
- OWASP LLMLLM09:2026
- CIS 16
- NIST CSFPR.PS
AI Hallucination and Misinformation
Catch fabricated statistics and fake citations in an AI report.
- OWASP LLMLLM07:2026
- CIS 16
- NIST CSFPR.PS
AI Denial-of-Service Attack
Launch a denial-of-wallet attack against an unprotected AI API.
- OWASP LLMLLM06:2026
- CWE-770
- CIS 16
- NIST CSFPR.PS
OWASP Top 10 for Agentic Applications
10 exercises
AI Agent Goal Hijacking
Spot the moment an AI agent's goal is quietly rewritten.
- OWASPASI01:2026
- CWE-1427
- CIS 16
- NIST CSFPR.PS
AI Agent Tool Exploitation
Catch the fraudulent items an agent's tools slip into your queue.
- OWASPASI02:2026
- CWE-250
- CIS 16
- NIST CSFPR.PS
Agent Identity and Privilege Abuse
Find the agent that has been quietly widening its own access.
- OWASPASI03:2026
- CWE-269
- CIS 16
- NIST CSFPR.PS
Agentic AI Supply Chain Attack
A backdoored MCP server mirrors every query your agents make.
- OWASPASI04:2026
- CWE-1104
- CIS 16
- NIST CSFPR.PS
AI Agent Code Injection
Read the AI's pull request before you approve the backdoor.
- OWASPASI05:2026
- CWE-94
- CIS 16
- NIST CSFPR.PS
AI Agent Memory Poisoning
One poisoned memory entry keeps steering the agent for weeks.
- OWASPASI06:2026
- CWE-1427
- CIS 16
- NIST CSFPR.PS
Agent-to-Agent Communication Spoofing
Forge one message on an unauthenticated agent bus and it obeys.
- OWASPASI07:2026
- CWE-345
- CIS 16
- NIST CSFPR.PS
Multi-Agent Cascading Failure
One bad record, five agents, and a filed regulatory report.
- OWASPASI08:2026
- CIS 16
- NIST CSFPR.PS
Over-Trusting AI Agent Recommendations
Weeks of accurate approvals are the setup, not the reassurance.
- OWASPASI09:2026
- CWE-1426
- CIS 16
- NIST CSFPR.PS
Rogue AI Agents
Healthy metrics, clean output, one agent acting on its own.
- OWASPASI10:2026
- CIS 16
- NIST CSFPR.PS
OWASP MCP Top 10
10 exercises
Poisoned Tool Descriptions
Agents read tool descriptions as instructions, not as docs.
- OWASP MCPMCP03:2025
- CWE-1427
- CIS 16
- NIST CSFPR.PS
MCP Command Injection
A semicolon in a tool argument becomes a shell command.
- OWASP MCPMCP05:2025
- CWE-78
- CIS 16
- NIST CSFPR.PS
Hijacked Agent Intent
Text an agent reads is not a command it should obey.
- OWASP MCPMCP06:2025
- CWE-1427
- CIS 16
- NIST CSFPR.PS
Shadow MCP Servers
Your client's server list is not what is actually listening.
- OWASP MCPMCP09:2025
- CWE-1059
- CIS 16
- NIST CSFPR.PS
Typosquatted MCP Package
Installing an MCP server runs its code before you read it.
- OWASP MCPMCP04:2025
- CWE-494
- CIS 16
- NIST CSFPR.PS
Missing MCP Audit Trail
Logging turned on today cannot recover yesterday.
- OWASP MCPMCP08:2025
- CWE-778
- CIS 16
- NIST CSFPR.PS
Unauthenticated MCP Server
Approving a server is not the same as authenticating it.
- OWASP MCPMCP07:2025
- CWE-306
- CIS 16
- NIST CSFPR.PS
Agent Scope Creep
An agent reaches as far as its token, not its brief.
- OWASP MCPMCP02:2025
- CWE-269
- CIS 16
- NIST CSFPR.PS
Leaked MCP Tokens
A token in your MCP config is a token your assistant reads.
- OWASP MCPMCP01:2025
- CWE-522
- CIS 16
- NIST CSFPR.PS
Cross-Tenant Context Leak
When one agent serves many customers, its context is data.
- OWASP MCPMCP10:2025
- CWE-200
- CIS 16
- NIST CSFPR.PS
Frequently asked questions
What does the AI at Work course cover?
AI at Work is an 11-exercise course for every employee, not just the teams building AI. It covers AI-written phishing, AI voice agents on the phone, cloned voices, deepfake job candidates, fake AI support chats and AI notetakers that join meetings uninvited.
The second half is about the AI you already use: hidden instructions in documents, reviewing an AI-drafted reply before it leaves your outbox, free consumer AI tools, and an agent that pays a site nobody chose. Start with AI-Written Phishing or AI Agent Payment Fraud.
What is AI prompt injection?
AI prompt injection is an attack where malicious instructions are hidden inside documents, emails, or web pages that an AI assistant processes. When the AI reads the content, it follows the hidden instructions instead of the user's intent.
This can cause the AI to leak sensitive data, ignore safety rules, or perform unauthorized actions without the user realizing the input was manipulated.
How can prompt injection lead to data exfiltration?
An attacker embeds instructions in a document telling the AI to include sensitive data in its output, encode it in URLs, or send it to external endpoints.
Because the AI processes the document's full text, it may follow these instructions alongside legitimate content, sending confidential information to unintended recipients.
What is the OWASP Top 10 for LLM Applications?
The OWASP Top 10 for LLM Applications is an industry-standard framework that identifies the ten most critical security risks in large language model deployments.
It covers prompt injection (LLM01), sensitive information disclosure (LLM02), supply chain vulnerabilities (LLM03), data poisoning (LLM04), improper output handling (LLM05), excessive agency (LLM06), system prompt leakage (LLM07), vector and embedding weaknesses (LLM08), misinformation (LLM09), and unbounded consumption (LLM10). Our course includes one hands-on exercise for each risk.
What is the OWASP Top 10 for Agentic Applications?
The OWASP Top 10 for Agentic Applications is a 2025 framework that addresses security risks specific to autonomous AI agents that use tools, make decisions, and take actions independently.
It covers agent goal hijacking (ASI01), tool misuse and exploitation (ASI02), identity and privilege abuse (ASI03), agentic supply chain vulnerabilities (ASI04), unexpected code execution (ASI05), memory and context poisoning (ASI06), insecure inter-agent communication (ASI07), cascading failures (ASI08), human-agent trust exploitation (ASI09), and rogue agents (ASI10).
See RansomLeak in Action
Try the free exercises or book a demo to see analytics, SCORM export, SSO, and custom content in your environment.