Community-Driven · AI Application Security

Security for the AI stack.

We build and teach AI application security: threat modeling, red teaming, and guardrails for LLM apps, RAG systems, and AI agents.

Hop 1
Input
Malicious user input
Hop 2
Prompt
Prompt injection
Hop 3
Retrieval
Poisoned context
Hop 4
Model
Unsafe generation
Hop 5
Tool Call
Over-permissioned actions
Hop 6
Action
Unintended side effects
What We Do

Four areas. One attack surface.

Why We're Different

Prompts are an attack surface. Treat them like one.

The Evolution

1

Traditional AppSec

Focuses on code vulnerabilities and standard network defenses.

2

AI Features Bolted On

Adding wrappers around APIs without securing the underlying model interactions.

3

Security by Design

Security designed around the model, retrieval, and tools.

Understand Context

Evaluate the whole system, not just the model in isolation.

Test Adversarially

Simulate real-world attacks to find prompt injections.

Constrain Tool Use

Apply least privilege to agents and external integrations.

Keep Humans in Control

Ensure transparency and oversight for automated actions.

What We're Building

Projects in progress.

Prompt Injection Test Harness

ConceptTesting Tool

An automated testing framework that probes LLM applications for direct and indirect prompt injection vulnerabilities using structured attack patterns.

Agent Permission Analyzer

ConceptAnalysis Tool

A static analysis tool that maps agent tool-call permissions, identifies over-privileged configurations, and suggests least-privilege boundaries.

RAG Poisoning Checker

ConceptDefense Tool

A validation layer for RAG pipelines that detects poisoned documents, manipulated embeddings, and suspicious retrieval patterns before they reach the model.

Learn With Us

AI security is a shared problem.

We learn in the open — sharing techniques, building exercises, and breaking things together so everyone ships safer AI.

Explore the Community
Engineering Principles

Built with security as a foundation.

Least privilege by default

Components operate with minimal necessary access rights.

Human oversight at every boundary

Critical decisions always involve human confirmation.

Evaluation before claims

Rigorous testing validates security assertions before use.

Explainable findings

Security events are documented clearly and concisely.

Responsible disclosure

Vulnerabilities are handled ethically and transparently.

Shipping an AI feature and not sure how it fails?