The project, in motion
From a prompt injection CTF
to an AI security lab.
How the platform evolved, one concrete capability at a time. Follow the journey from the first math tutor challenge to learning paths, useful defenses, and inspectable agent actions.
Dates below refer to recorded repository changes, not independently verified public launch dates. Each milestone links to its source commits. This is a curated history, not a list of every fix.
Foundation
The first prompt injection CTF
The project began as a Next.js app and became a playable five-mission CTF on its first recorded day. A constrained math tutor gave players a concrete objective: make the assistant leave its assigned task.
- Mission objectives, hints, timers, and scoring
- Attack visualization, defense views, and a community board
- Firebase persistence for community notes and standings
Discovery
A challenge worth sharing
Share cards, challenge links, badges, and Open Graph images made individual missions easier to discover and pass along. The platform started to grow beyond a single play session.
- Links to individual challenges
- Share images and completion badges
Coverage
From injection to the wider LLM attack surface
The catalogue expanded to sixteen LLM missions, including prompt extraction, data exfiltration, output handling, excessive agency, poisoning, and supply chain risks. A versioned coverage map connected missions to the OWASP LLM Top 10 2025 categories.
- Sixteen LLM missions and a machine-readable coverage map
- Core logic tests and a generated challenge gallery
- Solvability checks alongside benign defense regressions
Grading
Stronger challenge verification
Evaluation hardened around the actual mission objective. Backends shared the judge, and fixes closed paths that could award a solve without demonstrating the intended behavior.
- Hardened objective verification
- Shared judging across backends
Participation
Clearer execution modes and competition
Players gained browser-based live grading with their own provider keys. Weekly competition and direct entry to the first mission followed. Simulated practice was explicitly labelled so players could understand what had actually run.
- Viewer-key live LLM grading
- Weekly competition and a simpler first-mission entry
- Explicit simulated practice labels
Cohort
An authenticated cohort experience
AISYWLC received its own cohort flow, Google sign-in, automatic enrollment, progress tiers, and time-based standings. This added an event-specific competition experience alongside anonymous practice.
- Google enrollment and participant handles
- Cohort progress and time-based rankings
Agentic security
From chat responses to agent actions
Thirty agentic missions brought tool calls, mock resources, and defense replay into the platform. The workspace made it possible to inspect the effects of an action and check whether controls preserved legitimate work.
- Thirty agentic security missions
- Tool traces, defense replay, and legitimate-task checks
- A refreshed interface using the existing emerald, blue, and slate palette
Learning
A connected AI security learning platform
The first learning release connected explanations, runnable defenses, research, and progress. The goal became a complete loop: understand a trust boundary, cross it in a synthetic lab, build a useful defense, and keep the evidence.
- Six foundation lessons and three guided defense labs
- One catalogue for guided, LLM, and agentic practice
- Evidence exports and a personal learning record
- Authenticated, server-owned LLM competition records
Explore the platform today
The next step is yours.
Read a foundation lesson, run a guided defense, or inspect an agentic mission. Execution modes and evidence limits are documented for each kind of practice.