I test AI chatbots, LLM-powered apps, and AI agents for security
weaknesses. If you've deployed a chatbot, a RAG app, or any
agentic AI, it likely has gaps that traditional web pentesting
won't catch.
What I test for (OWASP LLM Top 10):
- Prompt injection — direct and indirect (hidden instructions in documents, web pages, or tool outputs)
- Jailbreaks and guardrail bypasses
- System prompt and sensitive data leakage
- Insecure output handling — XSS, SSRF, or RCE via model output
- Excessive agency — agents performing unauthorized actions or tool calls
- RAG and vector database weaknesses (data poisoning, cross-user leakage)
- Denial-of-wallet attacks that spike your API bill
Methodology:
Manual red-teaming combined with tools like Garak, PyRIT, and
Promptfoo, guided by the OWASP LLM Top 10.
What you get:
A clear PDF report with each finding, working proof-of-concept
prompts, severity rating, and recommended mitigations guardrails,
input/output filtering, system prompt hardening, and tool
permission scoping. One free re-check after you apply fixes.
What I need from you:
- Written permission to test
- Access to the chatbot, API, or test account
- Brief on intended behavior — what it should do, what it should refuse, what tools or data it touches
Honest note:
This field evolves fast. I follow current research and frameworks,
but no AI system can be made fully "secure" only harder to break.
I'll show you the gaps and how to close them.
Turnaround: 3–7 days depending on complexity.