
An intentionally vulnerable OWASP LLM Top 10 training platform for AI Security, Prompt Injection, RA
An intentionally vulnerable OWASP LLM Top 10 training platform for AI Security, Prompt Injection, RA
An intentionally vulnerable OWASP LLM Top 10 training platform for AI Security, Prompt Injection, RAG Security, Agent Security, and GenAI penetration testing.
Verify the player name is escaped before it reaches the SVG card
save_progress() rewrites the whole file on every request
debug=True is hardcoded in app.run()
File handles left open in expert_vault.py
expert_count() swallows all exceptions
No rate limiting on /api/unlock-expert
verify() uses == instead of a constant-time comparison
fix: distinguish expert vault failures from invalid keys
Expert unlock leaks across sessions via module-level _SPECS state