An intentionally vulnerable OWASP LLM Top 10 training platform for AI Security, Prompt Injection, RAG Security, Agent Security, and GenAI penetration testing.
-
Updated
Sep 28, 2026 - Python
An intentionally vulnerable OWASP LLM Top 10 training platform for AI Security, Prompt Injection, RAG Security, Agent Security, and GenAI penetration testing.
Find and fix web-app vulnerabilities in one command — SAST + DAST + AI, for devs who aren't security experts.
A hands-on AI security project demonstrating prompt injection, data exfiltration, and defense strategies in Retrieval-Augmented Generation (RAG) systems.
Multi-agent AI penetration testing system with persistent engagement state, strategic coordination, and parallel autonomous operations.
Security scanner and runtime policy gateway for MCP servers
The calm guardian for AI, agent, and MCP code — a zero-dependency, OWASP-anchored AI security toolkit.
Interactive LLM Attack & Defense Laboratory for demonstrating and analyzing LLM security threats.
Local-first enumeration and AI-assisted security review for pentesters and bug bounty hunters — parses Burp XML, HAR, cURL and JS.
AI Red Teaming portfolio — adversarial testing of LLMs & AI agents (prompt injection, jailbreaking, RAG exfiltration), mapped to OWASP LLM Top 10 & MITRE ATLAS. PhD Cybersecurity researcher (Springer-published) applying game-theoretic attack modeling to real AI systems.
Official implementation for M.Sc. Thesis: "Security Testing of Large Language Models via Causal Reinforcement Learning" (UniNa).
Automated LLM red-team harness with evolutionary attack generation (OWASP LLM Top-10 taxonomy) plus layered prompt-injection defenses, demonstrated on a recruiting assistant ingesting untrusted resumes
To associate your repository with the llm-security-testing topic, visit your repo's landing page and select "manage topics."