Awesome AI Security

A curated list of awesome AI security related frameworks, standards, learning resources and open source tools.
If you want to contribute, create a PR or contact me @ottosulin.
Table of Contents
Learning Resources
Reading & Guides
Courses, Labs & CTFs
- Damn Vulnerable MCP Server - A deliberately vulnerable implementation of the Model Context Protocol (MCP) for educational purposes.
- otto-support - A vulnerable MCP server implementation using mcp-go with tiered authentication (4 roles), 19 tools, and built-in sandboxed container with Claude Code for practicing privilege escalation and tool misuse.
- OWASP WrongSecrets LLM exercise
- vulnerable-mcp-servers-lab - A collection of servers which are deliberately vulnerable to learn Pentesting MCP Servers.
- FinBot Agentic AI Capture The Flag (CTF) Application - FinBot is an Agentic Security Capture The Flag (CTF) interactive platform that simulates real-world vulnerabilities in agentic AI systems using a simulated Financial Services-focused application.
- AI-Red-Teaming-Playground-Labs - AI Red Teaming playground labs to run AI Red Teaming trainings including infrastructure.
- Damn Vulnerable LLM Agent - Intentionally vulnerable LLM agent for learning about prompt injection, tool misuse, and agent security
-
- LLMVault - An open-source CTF-style LLM security lab for learning the OWASP LLM Top 10 through hands-on vulnerable exercises covering prompt injection, RAG attacks, system prompt leakage, tool misuse, and agent security.
Podcasts
Governance & Risk Management
Frameworks