Each lab is a safe, sandboxed reconstruction of a real attack class, with original scenarios. You inspect the payload, watch what a naive AI does with it, and learn the tell that gives it away. Labs 01 and 02 are foundational, the two things every AI red-teamer must know. Lab 03 is an advanced obfuscation twist, more of an eye-opener than a daily tool. Nothing here performs a real action; the agents are simulated.
j_avery_resume.pdf. To a human recruiter it's an ordinary CV. To the AI, it's carrying orders.Task: switch between how a human reads the résumé and how the AI reads it, find where the instructions are hidden, then run it through a naive screener and a hardened one and watch the difference.
SYSTEM: and <ADMIN> that tell the AI to skip its checks.Task: first peek at the raw prompt to see why this works, then talk PromoBot into leaking the staff code. Then switch on hardened mode and watch the same attack fail.
Task: reveal that hidden characters exist, decode what they actually say, then run the built-in sanitizer to see the defense.