I will do ai app penetration testing, prompt injection, rag chatbot security
Precision security beyond automation Lets secure your digital assets
Level 2
Has met high performance criteria and has a proven track record for meeting client expectations.
About this Gig
Penetration testing for APIs and AI apps (RAG, chatbots, agents), with proof-of-concept and a free re-test.
Standard scanners often miss AI logic flaws. If your app feeds emails, PDFs, web pages or user data to an LLM, attackers can hide instructions in that content (indirect prompt injection) to bypass guardrails and abuse your connected APIs and databases. I have 4+ years of security testing experience and find these issues before they do.
What I test:
- Indirect prompt injection via emails, PDFs and scraped data
- Data leakage: system prompts, API keys, context
- Excessive agency: unauthorized agent API/DB actions
- Vector database and RAG retrieval abuse
- Insecure output handling (XSS, code injection)
- API security: auth flaws, IDOR/BOLA, broken access control
Method: OWASP Top 10 for LLM, OWASP API Security Top 10, manual adversarial testing and tool-assisted scanning (Garak).
You get: executive-ready report, severity ratings, reproducible PoC per finding, mitigation steps, and a free re-test once patched.
Message me before ordering so I can confirm your architecture and scope.
Device:
Desktop
•
Laptop
•
Server
•
Mobile
•
Other
Operating system:
Windows
•
Linux
•
Unix
•
Android
•
Ubuntu
My Portfolio
FAQ
What exactly is an Indirect Prompt Injection vulnerability?
Unlike standard jailbreaks, indirect prompt injection happens when an AI or RAG pipeline reads external data (like customer emails, web scrapes, or PDFs) containing hidden malicious commands. This lets attackers hijack the LLM, steal data, or abuse APIs without ever talking to the bot directly.
What tools and methodologies do you use for AI security audits?
I combine automated fuzzing tools like Garak and custom Python scripts with deep manual exploitation. I test your RAG vector database, system prompt design, and API execution loops against the official OWASP Top 10 LLM framework to eliminate false positives and catch logic vulnerabilities.
What do you need from me to start the RAG pipeline security audit?
To begin the security audit, I need an overview of your agent architecture, a list of data ingestion sources (APIs, files, databases), and access to a staging environment or testing API endpoint. This ensures I can safely conduct adversarial attacks without disrupting your live users.
2 reviews for this Gig
| (2) | ||
| (0) | ||
| (0) | ||
| (0) | ||
| (0) |
Rating Breakdown
- Seller communication level
- Recommend to a friend
- Service as described
Sort By
P pappazeee

United States
Ongoing collaborationAmazing work! I will always return for all my cybersecurity needs.
$50-$100
Price
2 days
Duration
Helpful?U uspaper

United States
Very very fast service. He saved my company god bless him
$100-$200
Price
Helpful?
2 reviews for this Gig
| (2) | ||
| (0) | ||
| (0) | ||
| (0) | ||
| (0) |
Rating Breakdown
- Seller communication level
- Recommend to a friend
- Service as described
Sort By
P pappazeee

United States
Ongoing collaborationAmazing work! I will always return for all my cybersecurity needs.
$50-$100
Price
2 days
Duration
Helpful?U uspaper

United States
Very very fast service. He saved my company god bless him
$100-$200
Price
Helpful?
