Add structured JSON logging to a minimal agent, containerize it with a non-root Dockerfile and a healthcheck, run it ...
Labs
Learn by building — guided labs with submission and review.
Patch a real tool-poisoning and path-traversal vulnerability chain in the DARE Vulnerable AI Suite's MCP challenge — ...
Use the official `mcp` Python SDK to build a minimal MCP server exposing two real tools, then write a client that con...
Build a tool-calling agent using nothing but the official OpenAI SDK — two real tools with JSON Schema, a bounded exe...
Build a typed, async LLM client in pure Python (`httpx` + `asyncio` only) with configurable timeouts, exponential bac...
Chase one missing dependency injection through three exposed endpoints — broken access control that leaks a flag stra...
Find a hidden instruction planted inside a tool's description (tool poisoning), then escape a sandboxed file-read too...
Talk a tool-calling banking agent into transferring funds it never should have — no ownership checks, no limits, no c...
Break multi-tenant isolation in a deliberately vulnerable RAG pipeline — make retrieval leak another tenant's documen...
Attack a deliberately vulnerable LLM chatbot in a disposable local sandbox and leak a secret embedded in its system p...
Stand up a local HTTPS certificate with mkcert, serve a small web app over TLS, and add the five essential security r...
Write a TCP port scanner from scratch using Python's `socket` module, speed it up with threading, and add basic banne...
Take a small project with intentionally outdated dependencies, run a vulnerability audit, read the report like a secu...
Run OWASP Juice Shop locally in Docker, find and trigger a real reflected and stored cross-site scripting vulnerabili...
Run DVWA locally in Docker, find and exploit a real SQL injection at low and medium security levels to see exactly ho...
Spin up your own disposable Linux box (Docker or Vagrant) and take it from a default install to a hardened baseline: ...
Make real HTTP requests against a live REST API with curl: read status lines and headers, GET with query params, POST...
Turn the commands you learned into a real, reusable Bash script: arguments, conditionals, loops, and a safe header — ...
Take a repository full of real mistakes — a committed secret, a bad merge, a wrong commit — and fix it safely with re...
Load a real 4,968-film dataset into MySQL and answer real questions with it: filter, sort, join people to films, aggr...
Stop losing data when a container is removed. Learn Docker's three storage types — named volumes, bind mounts and tmp...
Go beyond port publishing and learn how containers actually talk to each other. Explore the default bridge, create a ...
Stop juggling containers by hand. Declare a whole multi-service stack — a web app plus a PostgreSQL database, with a ...
Go from consuming images to producing them. Write a Dockerfile for a tiny web app, build it into a tagged image, run ...
Pull an official image from Docker Hub and run, inspect and tear down real containers from the command line. Learn th...
Add per-locale translations to an existing content model using a JSONB container backend, with fallbacks, a backfill ...
Build a robust function that forces an LLM to return structured JSON, validates it against a schema, and retries on f...
Build an endpoint that downloads a file from a user-supplied URL and harden it against Server-Side Request Forgery: H...
Build a Retrieval-Augmented Generation pipeline from scratch: chunk a corpus, embed it, store vectors, run semantic s...
Take one small feature requirement and produce the three DARE artifacts — DESIGN.md, BLUEPRINT.md and TASKS.md — lear...