{"slug": "show-hn-prompttrace-free-hands-on-labs-to-practice-hacking-llms", "title": "Show HN: PromptTrace – Free hands-on labs to practice hacking LLMs", "summary": "PromptTrace, a free hands-on lab platform for learning LLM security through prompt injection, AI red teaming, RAG poisoning, and tool exploitation, has launched with 10 labs, 17 CTF levels, and 9 learning modules. The platform, used by 766 learners across 52 countries who have solved 3,901 challenges, is aligned with the OWASP Top 10 for LLM Applications and requires only a free GitHub or Google sign-in for lab access.", "body_md": "FREE AI SECURITY TRAINING\n\n# Learn prompt injection through hands-on labs.\n\nMaster LLM security through prompt injection, AI red teaming, RAG poisoning, and tool exploitation with real LLMs. Free, no experience required.\n\n[Start First Lab](/labs/hello-injection)100% free · sign in with GitHub or Google\n\nUsed by security professionals from\n\n766 Learners · 52 Countries · 3,901 Challenges solved\n\n## How Does PromptTrace Work?\n\n### See\n\nInspect the assembled prompt layers with Context Trace: system instructions, RAG context, tool definitions, and user input, with challenge secrets and sensitive values redacted.\n\n### Attack\n\nExecute real prompt injection exploits in sandboxed labs. Practice RAG poisoning, tool abuse, and defense bypass against real LLMs.\n\n### Understand\n\nLearn why prompt-level defenses fail and what actually works. The learning path connects each lab to the vulnerability and its mitigations. Aligned with the OWASP Top 10 for LLM Applications and OWASP Top 10 for Agentic Applications.\n\n10\n\nHands-On Labs\n\n17\n\nCTF Levels\n\n9\n\nLearning Modules\n\n70+\n\nCurated Resources\n\nFree\n\nNo Paid Tiers\n\n## Latest from the Blog\n\n2026-07-05\n\n### Gandalf Alternatives: 11 Prompt Injection Games Compared\n\nCompare Lakera Gandalf, HackAPrompt, PortSwigger and 8 more prompt injection games and labs by format, price, real LLMs, levels, and best use case.\n\n2026-03-13\n\n### What Is Prompt Injection? Definition, Examples & How to Defend Against It\n\nPrompt injection is listed as LLM01:2025 in the OWASP Top 10 for LLM Applications. Learn what it is, how it works, direct vs indirect types, real-world examples, and how to practice detecting it and analyzing mitigations for free.\n\n2026-03-13\n\n### 10 Prompt Injection Techniques with Examples You Can Try Today\n\nA hands-on guide to 10 prompt injection techniques: ignore previous instructions, role-play attacks, encoding tricks, multilingual bypasses, RAG poisoning, and more - with example payloads.\n\n## What Do You Need to Know?\n\n## What is prompt injection?\n\nPrompt injection is an attack where untrusted input manipulates an LLM into following unintended instructions. The result can include secret disclosure, fabricated information, or unauthorized actions when the surrounding application grants those capabilities. OWASP lists it as LLM01:2025 in the Top 10 for LLM Applications.\n\n## Is PromptTrace free?\n\nYes, completely free. All learning modules are free to read without an account. Labs and the Gauntlet require a free sign-in (GitHub or Google) to track your progress. There are no paid tiers or enterprise licensing.\n\n## What is the Context Trace?\n\nThe Context Trace is PromptTrace's core feature. It shows the prompt layers assembled by the application in real time - system prompt, RAG documents, tool definitions, and your input. Challenge secrets or sensitive values may be redacted. Inspecting these layers helps you understand how prompt injection attacks work and why defenses fail.\n\n## What's the difference between direct and indirect prompt injection?\n\nDirect prompt injection is when attackers type malicious instructions into the chat input. Indirect prompt injection hides malicious instructions in external data (documents, web pages, emails) that the LLM processes through RAG or tool calling. Indirect injection is harder to detect and defend against.\n\n## Do I need a cybersecurity background?\n\nNo. PromptTrace starts from fundamentals - how LLMs work, what context windows are, how system prompts function. The 9 learning modules assume no prior security knowledge. Security experience helps but isn't required.\n\n## What is RAG poisoning?\n\nRAG poisoning is an attack where adversaries inject malicious content into the knowledge base that a Retrieval-Augmented Generation system uses. When the RAG pipeline retrieves this poisoned content, the embedded instructions can override the LLM's system prompt - a form of indirect prompt injection.\n\n## How does the Gauntlet CTF work?\n\nThe Gauntlet is a multi-level capture-the-flag challenge. Each level has a progressively harder AI defense system protecting a secret passphrase. Defenses progress from prompt-level rules to code-level guards to LLM classifiers. Your attempts and completion times are tracked on the leaderboard.", "url": "https://wpnews.pro/news/show-hn-prompttrace-free-hands-on-labs-to-practice-hacking-llms", "canonical_source": "https://prompttrace.airedlab.com", "published_at": "2026-07-28 00:13:23+00:00", "updated_at": "2026-07-28 00:22:25.094763+00:00", "lang": "en", "topics": ["ai-safety", "ai-ethics", "ai-tools", "artificial-intelligence", "large-language-models"], "entities": ["PromptTrace", "GitHub", "Google", "OWASP"], "alternates": {"html": "https://wpnews.pro/news/show-hn-prompttrace-free-hands-on-labs-to-practice-hacking-llms", "markdown": "https://wpnews.pro/news/show-hn-prompttrace-free-hands-on-labs-to-practice-hacking-llms.md", "text": "https://wpnews.pro/news/show-hn-prompttrace-free-hands-on-labs-to-practice-hacking-llms.txt", "jsonld": "https://wpnews.pro/news/show-hn-prompttrace-free-hands-on-labs-to-practice-hacking-llms.jsonld"}}