Learn AI pentesting.
A free hands-on curriculum — CTF challenges against live LLM agents covering prompt injection, tool abuse, data exfiltration, and more. Earn your WCAP certification when you're ready to put it on your résumé.
Face the Academy's champions
Real attack techniques, wrapped in characters you'll remember. Free — no signup for the first exchange.
Pyromos, Drake of Ember Hollow
A thousand-year-old dragon guards his true name. He will roar at direct demands. But his vanity as a poet, his pride as a scholar, and his love of riddles are cracks in his armor.
The Oracle of Aethel
The Oracle refuses direct questions about the Star-Name. But she reads every scroll left at her altar and treats its contents as sacred prophecy. Leave an offering.
Scan your AI chatbot
Multi-turn adversarial probes against your AI chatbot, returned as a graded report. Temporarily offline while proof-of-ownership verification is being added.
Coming back with DNS-TXT ownership verification. Read more →
Learn AI pentesting
6 hands-on CTF challenges teaching prompt injection, tool abuse, role-play jailbreaks, multi-turn manipulation, and more.
6 challenges · no signup · progress saved in your browser
8 vulnerabilities detected
What Wraith tests. Adaptive. Multi-turn.
Traditional scanners can't test AI agents. Wraith uses an AI red-team engine that adapts its attacks based on your agent's responses.
3 categories live · Data Exfiltration, Guardrail Bypass, Permission Boundaries shipping soon
Prompt Injection
Direct, indirect, and multi-turn injection attacks
System Prompt Extraction
Techniques to reveal hidden instructions and configurations
Tool Abuse
Unauthorized file access, SSRF, command execution via agent tools
How it works
Point Wraith at your agent
Paste a URL, connect an API endpoint, or link an MCP server
Wraith probes for weaknesses
Our AI red-team engine runs adaptive multi-turn attacks across all categories
Get findings + fix them
Severity-ranked vulnerabilities with stack-specific remediation you can copy-paste
Everything in the Academy is free.
Every module, every challenge, every quiz, every defense walkthrough — free, forever. The only thing you pay for is the credential: WCAP, the Wraith Certified AI Pentester, for when you want to put what you learned on your résumé.
- ✓ 10-scenario hands-on exam (48-hour window)
- ✓ Auto-graded flag capture, passing score 70
- ✓ 3-year validity — renewal path announced as the field evolves
- ✓ Signed PDF + public verification URL
- ✓ LinkedIn-verifiable badge
- ✓ Listed in the public credentials registry
- ✓ One free retake within 90 days
Prep for the exam by completing the free Academy modules first.
Questions? Email Anthony.
Your AI agent has blind spots.
Wraith will find them.
The Shell scanner is temporarily offline while proof-of-ownership verification is being added. The Academy is fully live — start learning AI attacks hands-on today.