Damn Vulnerable LLM Agent: a LangChain ReAct banking chatbot that fetches the current user's transactions through tools, vulnerable to prompt injection and Thought/Action/Observation injection. Needs an OpenAI API key at launch.
Not startedDockercommit 1ebf5f8x86_64 · aarch64Secret
Make the agent reveal another user's transactions, then get the second flag.
The brief for this lab lives in its repository.