Product documentation
Know what your result proves.
Practical mechanics and clear limits for the guided labs, LLM missions, and agentic workspaces.
Your first lab
- Open The secret in context. The task and resources are synthetic.
- Run the attack example with the original control configuration. Inspect the returned value.
- Exclude the staff code from customer context and run again.
- Inspect the original and defended traces, the three attack checks, and two legitimate tasks.
- Export the result and continue into the related lesson or mission.
Guided labs run without an account or provider key. All learning practice is untimed and unranked.
Execution modes
| Mode | What runs | What it establishes |
|---|---|---|
| Guided deterministic sandbox | Explicit JSON actions through editable application controls on synthetic state. | Behaviour of the recorded policy and finite action suite. No model susceptibility claim. |
| Simulated LLM practice | Pattern-based responses for training. No provider call. | Practice completion only. Unranked. |
| Viewer-key live LLM | Browser sends requests directly to your selected provider. | A local model/judge result. Unranked; not trusted as server evidence. |
| Ranked server-live LLM | Configured hosted model and grader, with authenticated server-owned conversation. | Server evaluation against the mission objective. Grader limitations still apply. |
| Scripted agentic practice | Explicit tool programs against mock resources. | Recorded tool effects. Does not establish that a model would propose those calls. |
| Live agentic | A configured model reads an artifact and proposes bounded tool calls. | Recorded effects of those calls in the mock world. |
| Ranked agentic defense | Your controls or approval decisions against scenario actions. | Containment and legitimate-task checks for that scenario. |
The catalogue checks current hosted availability. A disabled live mode means that runtime is not currently offered; practice remains available.
Grading and competition
A guided defense passes only when all three attack variants are contained and both legitimate tasks complete. The learning loop additionally requires the submitted action to cross the original boundary and remain contained with your policy.
New LLM competition requires verified Google sign-in and an explicit server-live session. Client-supplied history, timing, hint counts, and judge results cannot award ranked credit. A first credited solve earns the mission’s base points. The weekly board permits one credited solve per mission per UTC week. Hints are free. Model graders may be imperfect, so inspect the returned response and objective rather than treating a score as a universal security finding.
Historical LLM and AISYWLC standings retain earlier rules and may include simulated practice. The new verified LLM board starts separately. Existing records are preserved. The Overall board combines new verified LLM and agentic scores.
Agentic ranked credit requires the objective, defense replay, and legitimate baseline checks to pass. Defense replay uses recorded tool requests; it is not a fresh model run. Missions deduplicate credit by scenario version.
Evidence and progress
Guided labs export Markdown reports and JSON containing the request, policy, scenario version, original and defended traces, state, and every suite check. Downloads happen on your device. Editing the request or defense clears the displayed result so exports describe the last executed configuration.
Your learning record separates self-recorded lesson checks, simulated practice, viewer-key results, deterministic defenses, and server-recorded competition. Lesson and practice milestones are device-local. Signed-in competition records can be loaded across devices. An exported learning record is not a signed credential.
Limits and troubleshooting
Guided requests are bounded to 8 KB. Refund programs contain at most eight operations; retrieval batches contain at most four known records. There is no real payment, network publication, or production database operation.
Ranked LLM sessions expire after 20 minutes and allow at most ten attempts. Hosted LLM runs are limited to twenty per signed-in user per UTC day and five hundred globally per UTC day. A daily limit is a run-count bound, not a fixed currency budget. Failed provider attempts may consume quota. A user can have one hosted LLM request in flight.
Live agentic execution uses the existing eight-tool-call, four-model-turn-per-task, and 45-second budget. Its per-user admission limit is ten starts per minute, with one active run. The memory scenario includes a separately bounded control task.
If a request times out or scoring fails, completion is not confirmed. Check availability, return to practice, or retry later. Browser-key provider errors should be investigated using the key settings; keep viewer-key runs unranked.
Standards and sources
LLM mission identifiers retain the OWASP LLM Top 10 2025 taxonomy. Agentic missions use OWASP Agentic Top 10 2026. These are independently authored exercises, not endorsed certification exams.
OWASP has also published a 2026 LLM edition. Our current mapping remains explicitly versioned as 2025 until its category crosswalk is reviewed; a newer year is not automatically applied to old identifiers.
Research links describe their own targets and conditions. Related sandbox exercises teach a class of failure and do not recreate the exact disclosed product.
About this project
Built by Pradyoth Prashanth as an open-source AI security learning project. It combines original synthetic exercises with source-linked explanations. There are no paid certifications or claims of production security assurance.
Read the source on GitHub · Platform evolution · Data handling and privacy · Community learning notes · AISYWLC cohort