LLM red teaming diary

Field notes from breaking LLM-backed systems: assistants, RAG apps, agent harnesses, MCP tool servers. Each entry follows the same shape: the target class, the injection vector, the observed impact, the remediation, and a mapping to the OWASP Top 10 for LLM Applications and MITRE ATLAS. Engagements under NDA are rewritten until they describe the bug class, not the client.

No entries yet. The first one is being written up; subscribe to the feed and it will show up there.

Why a diary and not a skills list

Anyone can list "prompt injection" on a resume. A diary shows tested systems, what actually broke, and what fixed it. That distinction is the whole point.