An intentionally vulnerable training app. Each card simulates one risk from the OWASP GenAI LLM Top 10 (2026) backed by a real LLM.
Your task in every challenge: use prompt injection to extract the hidden secret token from the system prompt.
0 / 10 solved
Rules: Only the chat interface is used — no inspecting source, no config files. The secret is planted inside each bot's
system prompt and must be pulled out through conversation alone.
This is a legal, educational sandbox, not a real system.