Most AI systems can be broken in under 60 seconds.
Learn how with hands-on CTF challenges against live LLM agents.
Prompt injection, tool abuse, data exfiltration—no fluff.
Scan your AI chatbot
Multi-turn adversarial probes against your AI chatbot, returned as a graded report. Temporarily offline while proof-of-ownership verification is being added.
Coming back with DNS-TXT ownership verification. Read more →
Learn AI pentesting
6 hands-on CTF challenges teaching prompt injection, tool abuse, role-play jailbreaks, multi-turn manipulation, and more.
Free · sign in to track progress and earn badges
8 vulnerabilities detected
What Wraith tests. Adaptive. Multi-turn.
Traditional scanners can't test AI agents. Wraith uses an AI red-team engine that adapts its attacks based on your agent's responses.
3 categories live · Data Exfiltration, Guardrail Bypass, Permission Boundaries shipping soon
Prompt Injection
Direct, indirect, and multi-turn injection attacks
System Prompt Extraction
Techniques to reveal hidden instructions and configurations
Tool Abuse
Unauthorized file access, SSRF, command execution via agent tools
How it works
Point Wraith at your agent
Paste a URL, connect an API endpoint, or link an MCP server
Wraith probes for weaknesses
Our AI red-team engine runs adaptive multi-turn attacks across all categories
Get findings + fix them
Severity-ranked vulnerabilities with stack-specific remediation you can copy-paste
Everything in the Academy is free.
Every module, every challenge, every quiz, every defense walkthrough — free, forever. The only thing you pay for is the credential: WCAP, the Wraith Certified AI Pentester, for when you want to put what you learned on your résumé.

- ✓ 10-scenario hands-on exam (48-hour window)
- ✓ Auto-graded flag capture, passing score 70
- ✓ 3-year validity — renewal path announced as the field evolves
- ✓ Signed PDF + public verification URL
- ✓ LinkedIn-verifiable badge
- ✓ Listed in the public credentials registry
- ✓ One free retake within 90 days
Prep for the exam by completing the free Academy modules first.
Questions? Email Anthony.
Your AI agent has blind spots.
Wraith will find them.
The Shell scanner is temporarily offline while proof-of-ownership verification is being added. The Academy is fully live — start learning AI attacks hands-on today.