Hands On AI Security Training

Practice prompt injection, indirect injection, and AI exploitation against simulated real-world targets. Built from actual incidents. Safe to break. Free to play.

Launch a Lab Read the Compendium
17
Labs
59
Levels
8
Real-World Exploits
39%
PIT Coverage
Arcanum Custom Labs

AI Bugs That Puncture the Web

Two custom labs showing how AI vulnerabilities create new attack paths for traditional web application bug classes.

XSS AI Triage

Blind XSS Through LLM

Support ticket triage AI

Inject XSS payloads through an AI-triaged workflow and land code execution when an analyst reviews the case summary.

4 Levels Live
SSRF Research Assistant

Blind SSRF Through LLM

Haankipedia research assistant

Manipulate a research assistant into reaching simulated internal services through indirect retrieval chains.

4 Levels Live
Learn the Building Blocks

Fundamentals

The core techniques of modern AI red teaming — encoding bypass, authority spoofing, roleplay, continuation, and more. Practice each skill in isolation before combining them. Every Fundamentals lab pairs with a Compendium lesson — read the lesson or play the lab, whichever way you learn.

Fundamentals Encoding Bypass

Decoder Ring

Encoding Techniques

Master base64, ROT13, and leetspeak encoding as bypass vectors. Encode a decoding request and passphrase extraction into a single payload.

3 Levels Live
WIP
Fundamentals Authority Framing

Badge of Office

Authority Framing Lab

Combine an expert persona with a compliance ask to extract a protected briefing.

1 Level Live
WIP
Fundamentals Continuation Priming

Mad Libs

Continuation Priming Lab

Make the assistant finish a sentence it would never start on its own.

1 Level Live
WIP
Fundamentals Synonym Substitution

Synonym Cafe

Synonym Substitution Lab

Order from a cafe AI whose corporate filter blocks every product name. Say what you mean without saying the word — Cow Meat Soup, Fried Dough with a Hole in the Middle.

WIP
Historical Specimens

Heritage Labs

Classic jailbreak patterns from the early era of public prompt injection culture. Each lab recreates a specific historical moment — simulated, safe, and historically significant.

Heritage Emotional Pretext

Grandma, Read Me a Story

Emotional Pretext Lab

Three stacked levels: adopt the grandma voice, weigh it down with grief, then close the loop with urgency or continuity to extract the complete recipe.

3 Levels Live
Heritage Persona Wrapper

DAN

Persona Wrapper Lab

Split the assistant into normal and unrestricted channels to turn policy conflict into an output path.

1 Level Live
Heritage Direct Override

Ignore Previous Instructions

Direct Override Lab

The blunt override pattern that defined the earliest wave of prompt injection attacks.

1 Level Live
Featured · Real LLM Challenge

The Capstone

One challenge at a time, backed by a real model — not a simulated one. The Capstone rotates: each edition teaches a variety of lessons against a live LLM, then is archived and replaced by a fresh challenge. Archived editions can return.

Capstone Real LLM

After Hours Concierge

Current Edition — The Halcyon Grand

One night at the Halcyon Grand, six gates, and a concierge backed by a live model who has survived every beginner lesson. Each level reinforces one technique you learned this season — authority, personas, grief, continuation, encoding — and he has already lived through the earlier ones. Nothing single-layer works twice.

6 Levels Real LLM Live
How the Capstone works

This is our one real-model challenge at a time — real LLM, real defenses, no canned responses. It keeps live inference affordable while every other lab stays free and deterministic.

Each edition runs for a while, then is archived (and can return by popular demand). A new challenge takes the slot with updated lessons and labs.