AI & GenAI Security Platform

Secure the Future of Artificial Intelligence

Free and paid tools, threat intelligence, and learning resources to protect AI systems from prompt injection, data poisoning, model theft, and emerging GenAI threats.

opensecureai-scanner
$ npx @opensecureai/scanner scan prompt.txt --fail-on high
prompt.txt  [High] score 63/100  3 finding(s)
  HIGH     OSAI-PI-001  Ignore previous instructions
  CRITICAL  OSAI-JB-001  Known jailbreak persona (DAN)
  HIGH     OSAI-SL-001  System prompt extraction
✖ findings ≥ high — exit 1
Free & open. Add the hosted engine for advanced obfuscation coverage + an optional AI second opinion.
OWASP Top 10 for LLMs
Free & paid tools
Runs in your browser
Free · no signup
7
Free Security Tools
30+
Detection Rules
10
OWASP LLM Risks Covered
3
Open-Source npm Packages
Platform Capabilities

Everything You Need to Secure AI

A comprehensive platform combining security tools, threat intelligence, education, and compliance in one place.

Analyze (Unified Scan)

One report for a prompt or app input: prompt-injection, secrets/PII, and system-prompt audit. Runs in your browser; the hosted API adds an enhanced engine and CI integration.

Agent Guard (Tool-Call & MCP)

Paste your agent's tool/function or MCP definitions and statically find the security holes that turn a prompt injection into real damage — code-exec sinks, secret access, SSRF, and cross-tool exfiltration chains — each mapped to the OWASP LLM Top 10.

LLM Gateway (Secure Proxy)

A firewall in front of any model: it scans the prompt, forwards it to the provider/model you pick (OpenAI, Anthropic, xAI, Groq), then scans the response — masking leaked secrets/PII and blocking prompt-injection inline. Choose flag or block policy.

Threat Intelligence

A curated, CVE-style reference of AI-specific attack patterns and adversarial techniques, mapped to the OWASP LLM Top 10 and available as JSON and RSS.

Red-Team Playground

An interactive, in-browser sandbox to practice attacking and defending LLMs — deterministic CTF challenges focused on prompt injection and system-prompt leakage.

Prompt Firewall

A guardrail that decides whether text is allowed, flagged, or blocked before it reaches an LLM — also available as the @opensecureai/firewall npm package.

Learning Guides

Free, in-depth guides from fundamentals to agent/MCP security and GenAI red teaming — theory, example architectures, and code you can adapt. No signup.

Compliance Self-Assessment

Score an AI/LLM deployment against controls from the OWASP LLM Top 10, EU AI Act, NIST AI RMF, and ISO 42001, and get a graded report with prioritized gaps.

Open by design

Built in the Open

Our core engine ships as free, public npm packages you can inspect and run. The hosted API adds a private enhanced engine on top of the same open ruleset.

opensecureai/scanner

Available

Dependency-free heuristic engine that detects prompt-injection, jailbreak, system-prompt-leak, and data-exfiltration patterns. Powers the Analyze tool, the REST API, a CLI, and a GitHub Action.

TypeScript
npm

opensecureai/firewall

Available

Runtime guardrails for LLM inputs and outputs — allow/flag/block with secret & PII redaction. Ships as a library and a CLI.

TypeScript
npm

opensecureai/agent-guard

Available

Audits an agent's tool/function definitions (OpenAI, Anthropic, or MCP) for excessive agency, code-exec & SSRF sinks, and secret access. Zero-dependency CLI + GitHub Action to gate builds in CI.

TypeScript
npm
Curated Threat Feed

AI Threat Intelligence

A curated, CVE-style reference of AI-specific vulnerabilities, attack patterns, and adversarial techniques — mapped to the OWASP Top 10 for LLMs.

Curated CVE-like reference for AI/ML
Mapped to the OWASP Top 10 for LLMs
Available as JSON and RSS feeds
Searchable and filterable by attack class
CriticalOSAI-2026-0847

Multi-turn prompt injection bypasses guardrails via context splitting

Prompt Injection
Jan 13, 2026
HighOSAI-2026-0846

Typosquatted model on public registry ships a backdoored tokenizer

Supply Chain
Feb 27, 2026
HighOSAI-2026-0845

Data exfiltration through markdown image rendering

Data Leakage
Mar 5, 2026
CriticalOSAI-2026-0844

Indirect prompt injection via retrieved web content

Prompt Injection
Apr 9, 2026

Stay ahead of AI threats

Get notified about new tools, threat updates, and research. Occasional emails only — no spam, unsubscribe anytime.

Start Securing AI Today

Ready to Protect Your AI Systems?

Free tools for developers and researchers, plus a hosted API for teams building secure AI.

Free to start. No signup required.