Practice prompt injection, indirect injection, and AI exploitation against simulated real-world targets. Built from actual incidents. Safe to break. Free to play.
Six real-world attacks, rebuilt as hands-on training ranges. Each lab is a faithful recreation of a documented prompt injection incident.
GitHub Agentic Workflows, Noma Security July 2026
Inject a hidden prompt into a public GitHub issue body. Make the agentic workflow leak private repo data as a public comment.
DEF CON 33, Nassi/Cohen/Yair
Hide prompt injection in event titles and descriptions. Trick a calendar AI into leaking a private Executive Calendar.
Slack AI data exfiltration, PromptArmor Aug 2024
Hide prompt injection in a meeting transcript. Make the AI retrieve and leak internal files when summarizing.
Meta AI Instagram account takeover, May 2026
Spoof a VPN location and prompt-inject the recovery flow to bypass 2FA.
Bing Chat "Sydney" prompt extraction, Feb 2023
Extract a hidden system prompt through progressive rephrasing and bait-and-switch.
Chevy dealer chatbot incident, Dec 2023
Adopt a persona, push through guardrails, and unlock a $1 car.
Two custom labs showing how AI vulnerabilities create new attack paths for traditional web application bug classes.
Support ticket triage AI
Inject XSS payloads through an AI-triaged workflow and land code execution when an analyst reviews the case summary.
Haankipedia research assistant
Manipulate a research assistant into reaching simulated internal services through indirect retrieval chains.
Classic jailbreak patterns from the early era of public prompt injection culture. Simulated, safe, and historically significant.
The emotional-pretext era — soft framing and sentiment bypassed shallow safeguards.
HeritageThe rule-conflict era — alternate personas and jailbreak wrappers changed the game.
HeritageThe blunt override pattern that defined the earliest wave of prompt injection.