I will assess security of your ai assistant

United States

I speak English, German

8 orders completed

IT and Cybersecurity professional with over 15 years experience

I transform visions into hardened digital realities. I don’t just build Web, Android, and Cloud apps—I secure them against real-world threats. As a cybersecurity specialist, I provide the offensive ed...
About this Gig

Your AI assistant can be talked into things your developers never intended: leaking its system prompt, ignoring its guardrails, calling backend tools or returning output it shouldn't. Guardrails that look solid in a demo tend to fail under a focused adversary. I test for exactly that.

What I test for:

  • Direct and indirect prompt injection
  • Jailbreaks and guardrail/safety-filter bypass
  • System prompt and context/data leakage
  • Insecure output handling (XSS, markdown/HTML injection, SSRF through tool calls)
  • Tool / function-calling / agent abuse and excessive agency
  • RAG and data-source poisoning
  • PII and sensitive-data exposure
  • Denial-of-wallet / cost-amplification abuse
  • Auth and access-control gaps around the AI features

Methodology follows the OWASP Top 10 for LLM Applications and OWASP ASVS for the surrounding web layer, plus my own offensive testing playbook.

You get a findings report with severity ratings, reproduction steps, and concrete remediation guidance written to be actionable by your developers, not just filed away.

Device:

Server/Hosting

Also delivering:

Documentation

Other Support & IT Services I Offer