Skip to main content
AI Security Lab

AI Security Lab

Interactive tools and practical frameworks for evaluating LLM, agentic AI, MCP, and RAG systems.

These tools are designed to help practitioners think through AI system risk, tool access, retrieval, autonomy, and control mapping. They are simplified educational aids, not formal audits or certifications.

4 interactive tools
0 data collected
100% runs in your browser
Personal educational tool: Personal educational tool. These tools are part of Andrew Dannenberger's personal professional website. They are simplified educational aids and approximations, not official assessments, audits, certifications, or formal security evaluations.
01 Live
Practical

AI System Risk Triage

Answer a set of questions about your AI system and generate a basic risk profile covering exposure, data sensitivity, tool access, control gaps, and key recommended controls.

⏱ 3–5 minutes
AI/LLM AI Agents MCP
Open →
02 Live
Practical

MCP Tool Risk Explorer

Select the tools an MCP-connected AI agent can access and see how risk changes across authorization scope, tool type, data sensitivity, and action impact.

⏱ 3–5 minutes
MCP
Open →
03 Live
Practical

MCP Security Checklist

An interactive checklist for securing MCP-connected AI agents, authorization, tool boundaries, human oversight, content trust, auditing, and supply chain. Track your coverage and copy the result.

⏱ 5 minutes
MCP
Open →
04 Live
Advanced

MCP Confused-Deputy Visualizer

Pick a confused-deputy attack against an MCP-connected agent, then toggle controls (instruction isolation, human approval, per-user authorization, least-privilege scope, parameter validation) to watch exactly where each attack gets blocked.

⏱ 5 minutes
MCP AI Agents
Open →

How This Lab Works

01

Practitioner-first

Tools are designed for security practitioners, developers, and AI adopters, not compliance officers. The goal is actionable thinking, not checkbox completion.

02

No backend, no tracking

All tools run entirely in your browser. No data is sent anywhere, no account required, no session is stored.

03

Grounded in public frameworks

Tools are inspired by the CIS Controls AI Companion Guides, OWASP LLM Top 10, and NIST AI RMF, simplified and explained in plain language.