I will assess security of your ai assistant
IT and Cybersecurity professional with over 15 years experience
About this Gig
Your AI assistant can be talked into things your developers never intended: leaking its system prompt, ignoring its guardrails, calling backend tools or returning output it shouldn't. Guardrails that look solid in a demo tend to fail under a focused adversary. I test for exactly that.
What I test for:
- Direct and indirect prompt injection
- Jailbreaks and guardrail/safety-filter bypass
- System prompt and context/data leakage
- Insecure output handling (XSS, markdown/HTML injection, SSRF through tool calls)
- Tool / function-calling / agent abuse and excessive agency
- RAG and data-source poisoning
- PII and sensitive-data exposure
- Denial-of-wallet / cost-amplification abuse
- Auth and access-control gaps around the AI features
Methodology follows the OWASP Top 10 for LLM Applications and OWASP ASVS for the surrounding web layer, plus my own offensive testing playbook.
You get a findings report with severity ratings, reproduction steps, and concrete remediation guidance written to be actionable by your developers, not just filed away.
Device:
Server/Hosting
Also delivering:
Documentation
Other Support & IT Services I Offer
FAQ
Do you need access to source code or model weights?
No. I work black-box by default — the same position an external attacker has. Gray/white-box review of integration code is available on the Full Engagement tier or as a custom order.
Can you test production?
I recommend a staging environment. If production is the only option, we coordinate timing and rate limits in advance to avoid impact.
Which framework do you follow?
OWASP Top 10 for LLM Applications for the AI layer, OWASP ASVS for the surrounding web application, plus my own offensive testing methodology.
Will I get something my developers can act on?
Yes. Every finding includes severity, reproduction steps, and specific remediation guidance — not a generic scanner dump.
Do you handle compliance (e.g. SOC2)?
Findings map cleanly to common controls and I can note relevant mappings, but these gigs are technical security assessments, not formal compliance audits. Message me if you need that framed differently.
Can you retest after we fix the issues?
Yes — retesting is included on the Comprehensive and Full Engagement tiers.

