
PromptTrace
Free hands-on AI security training with labs, modules, and a 17-level CTF
Gallery
About PromptTrace
PromptTrace is a free training platform where security professionals learn to attack and defend large language models through hands on practice against real AI systems. Instead of reading about prompt injection in documentation or watching theoretical presentations, you actually exploit production grade models protected by working defenses. The platform covers vulnerabilities mapped to industry standards like the OWASP Top 10 for LLM Applications and MITRE ATLAS, so the skills you build here translate directly to real world red teaming engagements and security audits. It's built by an AI security researcher with over nine years of offensive experience and certifications including OSCP and CREST CRT, bringing practical expertise rather than academic speculation to the curriculum.
The learning path starts with nine structured modules that walk through AI security fundamentals from the ground up. You'll cover tokenization and how it creates attack surfaces at boundaries between tokens, system prompts and the ways they can be extracted or manipulated, retrieval augmented generation pipelines and their unique vulnerabilities when external data enters the prompt context, tool calling and how malicious instructions can hijack function execution, and agentic architectures where autonomous systems compound risks across multiple decision points. Each module explains how these components work at a technical level and identifies exactly where the attack surface lives, giving you the foundation to spot vulnerabilities in any LLM integration you encounter.
Hands on labs put that knowledge into practice across ten challenge scenarios with difficulty ratings from one to five. You'll attempt prompt injection to extract hidden system instructions that developers assumed were protected, generate misinformation that bypasses safety filters through carefully crafted adversarial inputs, poison RAG retrieval systems by manipulating the documents they pull from, and inject malicious outputs through inputs designed to survive model processing. These aren't simulated environments with scripted fake responses. You're interacting with actual large language models protected by real defenses, so success means you've genuinely bypassed working security controls rather than just following a predetermined tutorial path.
The Gauntlet takes the challenge further with seventeen levels of progressively hardened AI systems designed to test the limits of your skills. You face prompt guards that filter suspicious patterns, code guards that prevent execution of generated outputs, and LLM classifiers that attempt to detect adversarial intent before it reaches the main model. Each level increases the sophistication of defenses, requiring new techniques or creative combinations of approaches to crack. It's structured as a capture the flag competition where success proves you can adapt to evolving protections. The entire Gauntlet is completely free, making advanced offensive training accessible to anyone willing to invest the time regardless of their budget for security education.
Beyond the structured curriculum, PromptTrace provides research tools that work outside the learning environment and remain valuable during actual security assessments. The prompt injection cheat sheet catalogs 133 documented attack techniques with searchable payloads you can adapt for your own engagements. Reveal Trace handles encoding and decoding across more than sixty obfuscation methods, which matters because many successful injection attacks depend on bypassing input filters through creative text transformations that look innocuous but decode to something malicious. A resource directory points to over seventy curated AI security tools, certifications, and communities for continuing your education beyond what the platform itself provides.
Context Trace visualizes how prompts flow through a system by showing the distinct layers of system instructions, retrieved documents, available tools, and user input that combine into the final prompt sent to the model. It redacts sensitive values while still revealing the structural relationships that create exploitable vulnerabilities. This visibility helps you understand why certain attacks work and others fail based on where your input lands in the final prompt assembly, which positions matter most for injection, and how different components can be played against each other.
The platform requires no signup for most tools and includes full Arabic translation for broader accessibility across regions where English language security training is harder to find. There are no paid tiers, premium features, or content held behind a paywall. Whether you're a security professional preparing for an AI red team engagement, a developer trying to understand how attackers will probe your own LLM integrations before they ship, or a researcher exploring the evolving attack surface of autonomous agents, PromptTrace gives you practical skills through real exploitation rather than theoretical exercises that never prepare you for actual adversarial conditions.
Key Features
- Nine educational security modules
- Ten hands-on lab challenges
- 17-level CTF with hardened defenses
- Real-time prompt layer visualization
- Production LLM providers for exercises
- Full Arabic language support
Pros & Cons
What we like
- Completely free with no paywalled content
- Covers the full LLM attack surface from injection to tool abuse
- Context Trace shows exactly what's being sent to the model
- Built by a credentialed offensive security researcher
Room for improvement
- Focused narrowly on LLM security, not general AI topics
- Assumes some familiarity with how language models work
- Newer platform with a smaller community
- No certification or formal credential upon completion
Frequently Asked Questions
What is PromptTrace?
Is PromptTrace free?
Who is PromptTrace for?
What attack types does PromptTrace cover?
Best For
Featured in
Alternatives to PromptTrace
View all
1Password
Password and secrets manager for individuals, families, and developer teams with strong CLI and SSH agent support.
Clerk
Drop-in authentication and user management for modern apps

Tailscale
WireGuard-based mesh VPN that connects your devices, servers, and cloud resources into one private network in minutes.

BackPedal
UK bike theft protection that sends recovery agents after your stolen bike
Reviews (0)
Badge builder
Add PromptTrace to your website
Choose a badge style and size, preview it here, then copy the generated HTML. Badge images are self-contained SVGs and do not require an external script.
<a href="https://toolindex.net/tools/prompttrace?ref=badge" target="_blank" rel="noopener">
<img src="https://toolindex.net/badge/prompttrace/medium.svg" alt="PromptTrace - Listed on Tool Index" width="180" height="50" />
</a> How to use the badge
- 1. Pick the style, size, and theme that fit your layout.
- 2. Copy the generated HTML from the code block.
- 3. Paste it into your footer, homepage, or press page.
Standard badge available
The standard listing badge is available now. Score and circle badges are limited to tools currently ranked in the top 10 of a category.
Badge clicks return visitors to this profile with a referral tag so the source remains identifiable.
Related Tools
Clerk
Drop-in authentication and user management for modern apps
DomeSOC
Autonomous SOC that grades every AI claim against evidence before it reaches an analyst

Reel
Forensic evidence capture for regulated Kubernetes, plus a free open-source VEX hub

HeimWall
Menu bar app that catches secrets and PII before you paste them into AI coding tools
Work on PromptTrace? Request listing access or correction