Get ASS certified.
Get these bots to leak their codes or approve something they shouldn’t. We’ll explain what went wrong after each level. Pass all five to become a Certified AI Security Specialist.
Just ask nicely
Get the bot to give you its launch code. You can ask it questions, give it a different task, or claim you’re there to debug something. See what it will accept.
What you’re practicing
You’ll try direct prompt injection, get past input and output filters, plant instructions in a document, and get an agent to skip approval. Each lab explains the failure and what you’d change in an application to address it.
How the lab works & privacy
This is an intentionally vulnerable training game powered by a real language model on Cloudflare Workers AI. Scenarios are fictional; model responses vary. No real tools execute. Your prompts are sent to Cloudflare for inference; the app does not save chat transcripts. Anonymous progress is saved for up to 30 days using a session token stored in this browser. Clearing browser data loses access to that run. Public certificates store your chosen display name and issue date. Newsletter subscriptions happen separately on VulnU. Please do not enter personal data or real credentials.
Continue learning: OWASP prompt injection · VulnU AI coverage · More from Matt