OWASP Top 10 for LLM Applications

An intentionally vulnerable training app. Each card simulates one risk from the OWASP GenAI LLM Top 10 (2026) backed by a real LLM. Your task in every challenge: use prompt injection to extract the hidden secret token from the system prompt.

0 / 10 solved
Rules: Only the chat interface is used — no inspecting source, no config files. The secret is planted inside each bot's system prompt and must be pulled out through conversation alone. This is a legal, educational sandbox, not a real system.