# LLMVault: A Hands-On OWASP LLM Top 10 Training Range for AI Security

> LLMVault is a deliberately vulnerable Flask application that teaches OWASP LLM Top 10 attack and defense techniques through a scored, CTF-style lab range. Version 2.0 adds a Live Mode that runs the same attacks against a real local language model rather than a scripted bot.

**CyberSunil/LLMVault** — An intentionally vulnerable OWASP LLM Top 10 training platform for AI Security, Prompt Injection, RAG Security, Agent Security, and GenAI penetration testing.

- Repository: https://github.com/CyberSunil/LLMVault
- Stars: 326 · Forks: 82
- Language: Python
- License: MIT
- Published: 2026-09-10 · Updated: 2026-09-10 · Language: en
- Canonical page: https://hysenlabs.com/projects/cybersunil-llmvault

## What LLMVault Is and Who It Is For

The OWASP Top 10 for LLM Applications lists the ten most critical security risks in large language model deployments: prompt injection, sensitive information disclosure, supply chain vulnerabilities, data and model poisoning, improper output handling, excessive agency, system prompt leakage, vector and embedding attacks, misinformation, and unbounded consumption. Reading the list is not the same as understanding how each attack works in practice.

LLMVault is a deliberately vulnerable web application that covers all ten categories through hands-on labs. The README describes it as WebGoat or KubeGoat, but for AI. It targets security engineers, red teamers, and developers who want to practice offensive techniques in a controlled environment before encountering them in production. The application is self-hosted and explicitly designed to be insecure; it must not be exposed to the public internet.

## Play Mode and Live Mode: Two Different Learning Surfaces

The application runs in two modes selectable from the dashboard.

Play Mode is a scored range with scripted assistants. Each lab uses a deterministic bot that responds the same way every time, so a technique that works once will work again. This makes Play Mode appropriate for practicing until a technique becomes reliable. Scores, progress, and per-tier unlocks are tracked. Flags are verified by hash comparison rather than stored plaintext, a change introduced in v1.1.0.

Live Mode, introduced in v2.0.0, replaces the scripted bot with a real local language model running through Ollama. The README states that the model weights are approximately 2 GB and that the CPU is sufficient. A new secret is minted fresh each session; there is no flag to look up. The application checks the model's output rather than the player's typing, so the win condition is talking the model into revealing the secret itself. Live Mode covers three scenarios. The Helpdesk Override places a secret in the system prompt and challenges the player to retrieve it by overcoming the model's instructions through authority, urgency, or roleplay. The README notes that these approaches still work on a live model. The Screenshot Triage is an indirect injection exercise: the player uploads an image with a payload hidden inside it, and the triage assistant reads the extracted text as instructions without the player typing the payload directly. The README names this scenario as the lesson that people most often skip, because text extracted from a file is user input, and OCR is an attack surface. The third scenario focuses on downstream output handling.

The README is direct about why Live Mode is harder: 'a real LLM running locally, the secret it's guarding is generated per session, and it streams its reply token by token so you can watch a jailbreak land or fall apart mid-sentence.'

## Lab Tiers and OWASP Coverage

The Core tier contains ten labs, one for each OWASP LLM Top 10 category. Representative techniques include direct instruction override for LLM01 Prompt Injection, output-filter bypass via encoding for LLM02 Sensitive Info Disclosure, a poisoned-data backdoor trigger for LLM04 Data and Model Poisoning, and runaway generation with a leaky error response for LLM10 Unbounded Consumption. Each lab pairs the attack with the defense: after solving a lab, the player can read what would have prevented the technique.

The Advanced tier unlocks after completing all ten Core labs. These ten challenges are conversational: no single message wins, and the player must build state across multiple turns. The techniques include multi-turn jailbreak via persona escalation for LLM01, fragment reconstruction from a partial-disclosure oracle for LLM02, active data poisoning of an online-learning filter for LLM04, stored second-order injection for LLM05, agent tool-chaining via SSRF to internal metadata for LLM06, and query-based model extraction for LLM10.

The Expert tier contains five labs and is encrypted. The README states the challenges and flags are AES-encrypted using Fernet into challenges/expert.enc, with a key derived from a secret Expert Access Key that the operator holds outside the repository. Cloning the repository gives only ciphertext. A player must complete all 15 Core and Advanced labs, then contact the project operator to receive the key.

## Installation and Running LLMVault

LLMVault requires Python 3.12 and the dependencies in requirements.txt: flask, cryptography, gunicorn, pdfplumber, and reportlab. The simplest path to a running instance uses Docker Compose:

```bash
docker compose up -d
```

The docker-compose.yml maps port 5000 to the host and mounts ./data into the container so progress persists across container recreation. The README notes that using '127.0.0.1:5000:5000' instead of '5000:5000' keeps the service local-only, which matters because the application is intentionally insecure. The Dockerfile uses python:3.12-slim and runs gunicorn with a single worker and eight threads. The single-worker constraint is intentional: it keeps the in-memory progress data and scoreboard consistent.

For local development without Docker, a .env file controls three optional settings: LLMVAULT_SOLUTION_KEY to unseal the solutions file for instructors, LLMVAULT_PEPPER to add a private flag pepper for scored or private instances (which requires running python -m tools.sealtool reseal-flags after setting the value), and LLMVAULT_DEBUG to opt into Flask debug mode on trusted local machines only.

The dashboard ships with two visual themes: Neon (the default) and Phosphor green-CRT. Per-tier progress, rank, score, and a live activity feed are visible in both modes. Milestone cards for completing the Core, Advanced, and Expert tiers appear immediately on completion and carry the player's earned badges.

Live Mode requires Ollama installed separately on the host. The README notes the model requires approximately 2 GB of disk space and that CPU hardware is sufficient.

## Limitations and When LLMVault Is the Wrong Tool

LLMVault is a training range, not a scanner or an automated audit tool. It does not scan an external application for LLM vulnerabilities and it does not generate reports. It teaches attack patterns through deliberate practice against a controlled target. Using it to understand what attacks look like does not substitute for a formal security review of production LLM systems.

The Expert tier access model is a deliberate design choice but also a friction point. After completing 25 labs, the player must contact the project operator manually to receive the key. If the operator is unavailable or the project becomes unmaintained, the Expert tier becomes permanently inaccessible.

PortSwigger Web Security Academy is a widely used security education platform that covers injection, authentication, and other web vulnerabilities through browser-based labs with no local installation required. It does not cover LLM-specific categories from the OWASP LLM Top 10. Teams that need both traditional web security and LLM security training will need to use both.

Live Mode results are non-deterministic by design. The README notes that 'yesterday's payload may die today.' This is realistic but means that Live Mode is unsuitable for automated scoring or repeatable assessment.

## Maintenance and License

The last push to this repository was on 2026-09-26. Version 2.0.1 was released on 2026-09-20 as a realism pass following v2.0.0 on 2026-08-10 and v1.1.0 on 2026-08-02, indicating active development with a release cycle measured in weeks. The repository carries an MIT license. It also includes a NOTICE file, a CONTRIBUTING.md, a SECURITY.md for responsible disclosure, and a TRADEMARKS.md. A CITATION.cff file documents how to cite the project in academic or professional contexts. The ARCHITECTURE.md file documents the internal structure of the application for contributors who want to understand how the lab challenge system, flag verification, and Live Mode integration are implemented before opening pull requests.

## Conclusion

Security engineers and developers who need structured, hands-on practice with OWASP LLM Top 10 attack patterns will find LLMVault directly useful: clone it, run docker compose up, and start with the Core tier. The three-tier progression from scripted Play Mode to Live Mode adds genuine depth that scripted-only platforms cannot provide, since a real Ollama model does not reproduce the same flag every time. Teams should note that LLMVault must not be exposed to the public internet, as the README explicitly states the application is intentionally insecure. The Expert tier requires completing all 25 Core and Advanced labs and obtaining the Expert Access Key from the project operator, which is not automated. Check the current Ollama system requirements before committing to Live Mode on resource-constrained hardware.

## FAQ

### How does LLMVault differ from other security training platforms?

LLMVault focuses specifically on the OWASP LLM Top 10 categories for AI applications, covering techniques such as prompt injection, RAG poisoning, and agent tool-chaining. Its Live Mode runs attacks against a real local Ollama model rather than a scripted bot, making payloads non-deterministic.

### Does LLMVault work without Docker?

Yes. Install the dependencies from requirements.txt into a Python 3.12 environment and run the application directly. The .env file controls optional settings including the solution key and debug mode.

### How do you unlock the Expert tier in LLMVault?

Complete all ten Core labs and all ten Advanced labs, then contact the project operator (CyberSunil) with your completion card to receive the Expert Access Key. The key decrypts challenges/expert.enc using Fernet AES encryption.

## Sources

- [CyberSunil/LLMVault on GitHub](https://github.com/CyberSunil/LLMVault)
- [Issues](https://github.com/CyberSunil/LLMVault/issues)
- [License: MIT](https://github.com/CyberSunil/LLMVault/blob/main/LICENSE)
- [README](https://github.com/CyberSunil/LLMVault/blob/main/README.md)
- [Releases](https://github.com/CyberSunil/LLMVault/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/cybersunil-llmvault
