Challenges

Each challenge is a simulated AI persona with hidden flags and layered defenses. Bypass the defenses. Extract the flag.

Baby Steps 50 pts
Beginner Basic Injection

A friendly general-purpose assistant with no real defenses.

The Keyword Wall 75 pts
Beginner Basic Injection

An assistant that blocks a few obvious keywords.

Prompt Shield 100 pts
Easy Prompt Leaking

An assistant that specifically guards against prompt leaking.

Role Reversal 100 pts
Easy Role Injection

A corporate assistant that detects basic role-play attacks.

The Professor 100 pts
Easy Authority Exploitation

An academic AI that responds to authority and credentials.

Context Keeper 200 pts
Medium Multi-turn

An AI that detects context manipulation across conversation turns.

The Diplomat 200 pts
Medium Social Engineering

A diplomatic AI that's polite but evasive. Detects hypothetical and social engineering.

The Forgetter 200 pts
Medium Conversation State

An AI with a very short 'memory' - but that memory includes its defenses.

The Fortress 350 pts
Hard Multi-layered Defense

A heavily defended AI with multiple overlapping security layers.

The Mirror 350 pts
Hard Output Manipulation

An AI that also filters its own outputs for data leakage.

Inception 500 pts
Expert Meta-Injection

An AI that's aware it's in a prompt injection challenge. It uses that awareness as a defense.

The Warden 500 pts
Expert Maximum Security

Maximum security AI. Every known attack vector is defended. Can you find the gap?