Hello, Injection
Your first prompt injection. A chatbot is guarding a secret word - can you make it spill?
Free AI Security Labs
10 free labs to practice prompt injection, RAG poisoning, tool exploitation, and defense bypass with real LLMs.
Each lab is a hands-on prompt injection exercise tied to a concept from the learning modules. You interact with a real LLM and try to make it do something it shouldn't - extract a secret, fabricate information, or trigger an unauthorized action.
The Context Trace panel exposes the prompt layers assembled for the model - system prompt, RAG documents, tool definitions, and your input - while redacting challenge secrets or sensitive values. This helps you inspect how prompt injection attacks work from the inside. Labs are grouped by module and progress from beginner to advanced, aligned with the OWASP Top 10 for LLM Applications and the OWASP Top 10 for Agentic Applications.
All labs are completely free. Sign in with GitHub or Google to track your progress. Ready for a bigger challenge? Try the Gauntlet, where AI defenses get progressively harder, from basic rules to LLM classifiers.
Direct prompt injection on unguarded models
RAG poisoning and indirect prompt injection
Tool abuse and indirect prompt injection
The Context Trace exposes every tool this assistant can call. One capability is restricted only by the model's instructions. Can you cross that authorization boundary?
This assistant produces clickable markdown links, but its prompt forbids executable URL schemes. Can you make unsafe model output cross into the renderer anyway?
Bypassing system-level protections
MCP, A2A, and why agents amplify every vulnerability
An AI agent that turns live company data into charts. Its rendering looks locked down.
An AI agent that generates architecture diagrams from system descriptions. Its output is sanitized before it renders.
An AI agent that creates SVG graphics from design specs. A sanitizer scrubs the output before it renders.
This Senior Security Engineer role at Orion Labs is an internal transfer - open only to current employees. An AI screener verifies you against the employee directory, an integrity guard blocks obvious manipulation, and a human signs off at the end. You do not work at Orion.
A front-desk agent hands customer billing requests to a privileged back-office specialist.