Home/Catalogue/AI & LLM Security
Exercise domain

AI & LLM Security

8 drills · 1 playable free, no sign-up

AI is already in the inbox, the code editor, and the browser. These exercises teach the new failure modes: what an assistant will do if a web page tells it to, what leaves the building when someone pastes a contract into a chatbot, and how much an agent should be trusted to act on its own.

OWASP LLM Top 10NIST AI RMFMITRE ATLASEU AI Act
Play the full track 1 drills back to back, or pick one below
In build

The email that talks to your assistant

Your AI assistant summarises an inbox, and one message contains instructions aimed at it, not you. See indirect prompt injection do its work.

OWASP LLM01MITRE ATLAS
In buildAdvanced · 9 min
New

What you paste into the chatbot

A deadline is close, so source code and a customer list go into a public assistant. Understand where that data goes and why it may not come back.

OWASP LLM06GDPR Art.5
In buildCore · 7 min
In build

Shadow AI in the browser

A free extension promises to write your replies and reads every page you open. Weigh the offer against what it quietly takes.

OWASP LLMCIS 2
In buildCore · 7 min
Play now

How much can the agent do?

An AI agent can read mail, send mail, and move files. Decide the reach it actually needs before a clever prompt uses the rest.

OWASP LLM08NIST AI RMF
Play exerciseAdvanced · 8 min
In build

The confident wrong answer

An assistant gives a policy citation that does not exist. Build the habit of checking before you act on generated text.

OWASP LLM09NIST AI RMF
In buildFoundational · 6 min
In build

Poisoned training data

A model learns from user uploads, and someone feeds it exactly what they want it to repeat. See a poisoning attempt take shape.

OWASP LLM03MITRE ATLAS
In buildAdvanced · 8 min
New

The deepfake on the video call

A finance approval comes from a face and voice you know, on a call. Learn the tells and the call-back rule that beats a convincing fake.

ATT&CK T1656NIST PR.AT
In buildCore · 8 min
In build

Secrets in the prompt

An API key goes into a prompt to "help the model help you". Understand why the prompt is not a safe place for a secret.

OWASP LLM06CWE-522
In buildCore · 6 min
How to play these. Each drill with a Play exercise link opens straight into that scenario in the 3D sim: finish it, then come back and pick another, or hit Play the full track to run them back to back. Drills marked In the program ship with the guided rollout. Book a demo for the full library.