Community

Learn AI security together.

A space for learning AI and cybersecurity together — sharing what we build, what we break, and what we find along the way. Whether you are just getting started or already shipping AI features, there is something here for you.

Curriculum

What we teach

Every topic maps directly to a hop in the AI request path. We deconstruct real vulnerabilities and examine defenses at each stage.

Hop 1
Input
Malicious user input
Hop 2
Prompt
Prompt injection
Hop 3
Retrieval
Poisoned context
Hop 4
Model
Unsafe generation
Hop 5
Tool Call
Over-permissioned actions
Hop 6
Action
Unintended side effects

Prompt Injection

Hop 1

How attackers manipulate prompts to override instructions, extract data, or change model behavior.

Retrieval Poisoning

Hop 2

How malicious content in document stores can influence RAG outputs and compromise retrieval integrity.

Agent Permissions

Hop 4

How over-permissioned tool calls let agents take actions they were never meant to, and how to constrain them.

Evaluation Basics

Hop 3

How to measure whether your AI system's security controls actually work — before and after deployment.

Participation

Ways to take part

Prompt Injection Workshop

PlannedWorkshop

Hands-on session covering direct and indirect prompt injection techniques, detection methods, and defense patterns.

Securing RAG Pipelines

PlannedWritten Guide

A written guide covering document validation, embedding integrity, and retrieval-layer defenses for RAG systems.

Agent Permission Exercises

PlannedOpen Exercise

Open exercises where you audit agent tool-call configurations and practice applying least-privilege principles.

Community Discussion

PlannedDiscussion Channel

An open channel for discussing AI security topics, sharing findings, and connecting with others working on these problems.

Want to learn or contribute?

Join our open learning track. Reach out to collaborate on exercises, suggest topics, or share your security research.

Join Community