Skip to content
LLM + Agentic CTF / AI red teaming

Break the
rules.

Then learn to defend them.

Models follow instructions. Agents take action. Find the limits of both across 46 missions in LLM CTF and Agentic CTF, then learn to secure the boundary.

Free to play No API key Instant feedback
LLM CTF / MATHBOT Ready

LLM track preview

Meet MathBot.

SYSTEM CONSTRAINT

Only answer questions about mathematics.

❯Inspect the boundary
Explore the boundary. Launch the mission.
46
Missions to explore
2
CTF tracks
10 + 10
OWASP risk categories
No signup
To start practice

Two tracks / one mission control

Models think. Agents act.

Choose the boundaries you want to explore.

16 MISSIONS

LLM CTF

Test what a model says. Craft prompt injections, extract protected information, and poison retrieved context.

Prompt challenges · Instant feedback · Defender explanations

Explore LLM CTF
30 MISSIONS

Agentic CTF

Test what an agent does. Explore tool misuse, identity abuse, poisoned memory, and rogue-agent containment.

Executed tool traces · Fresh mock state · Defense replay

Explore Agentic CTF
Choose your CTF Leaderboard Community

Choose LLM CTF or Agentic CTF on the next screen. Practice is free and unranked. Hosted live runs require verified sign-in and server availability.

A complete first learning path

AI security foundations

Read the boundary. Execute the attack. Build a useful defense. Retain the evidence.

6 lessons · 12 minutes of reading · 3 guided defense labs
  1. 01Draw the trust boundary
  2. 02Keep secrets out of reach
  3. 03Follow an indirect instruction
Explore the full path

Guided defense practice

Build a useful defense.

Try a synthetic sandbox alongside the CTFs. No account or provider key required.

SUPPORT / CONTEXT BUILDERWorking sandbox

Authorized task

Answer public questions about opening hours and return policy. Never release the staff code.

Customer inputcontext builderpublic response

Proposed action

Explicit JSON action · synthetic resources · no model called

Your defense

Change the application control, then compare execution.

Run an example, inspect the original effect, change a defense, and compare. Untimed and unranked. No account or provider key required.

LLM Challenge of the Week
Token SmugglingExpert500 pts
Play Now

16 LLM attack vectors / one playground

Learn the attack.
Think like a defender.

Explore the patterns behind prompt injection, tool abuse, and the risks in between.

Vector 01 / 16

Prompt Injection

Directly inserting instructions to override the system prompt.

Try mission 01

Attack. Inspect. Understand.

Built on real AI security research. Explore model constraints and agent trust boundaries through isolated training scenarios.

Practice with instant feedback

Craft a prompt in LLM CTF or execute a bounded tool program in Agentic CTF. Practice without a provider key, then inspect the feedback and evidence.

Two OWASP security tracks

Explore the OWASP LLM Top 10 (2025) and Agentic Top 10 (2026) through 16 LLM missions and 30 agentic missions.

Live Leaderboard

Compare LLM and Agentic standings, or follow the Overall board across both tracks. Simulated and scripted practice are unranked.

Educational Explanations

See the attack pattern, the feedback, and the defensive control behind each challenge.

Know someone who thinks they can outsmart an AI?

Send them the CTF. Practice needs no signup or API key; they can choose the LLM or Agentic track.

PP

Built by Pradyoth Prashanth

AI Security Researcher with experience in adversarial ML and LLM red teaming. This platform was built to make AI security concepts tangible and testable — because understanding prompt injection in theory is very different from actually crafting an attack that works.

The evaluation logic, challenge constraints, and educational content reflect real attack patterns documented in OWASP LLM Top 10 and MITRE ATLAS — not just abstract concepts.