# AI Goat (AIGoat) > AI Goat is a free, open source, intentionally vulnerable AI security playground for AI red teaming, built by the AI Security Consortium. It is an AI-powered e-commerce shop with an LLM chatbot (Cracky), a RAG knowledge base, MCP integrations and a tool-calling AI agent with memory. Learners attack and defend it through hands-on labs that run locally with Ollama: no cloud setup, no API keys. Key facts (v2.0): - 46 labs: 23 for the OWASP Top 10 for LLM Applications (2026), 12 for the OWASP Top 10 for Agentic Applications (2026), 11 for the OWASP MCP Top 10 (2025, beta). - Attack surfaces: LLM chat, RAG, a tool-calling agent, an MCP client and an MCP host (official MCP Python SDK over stdio, four local servers). - Capstone: Agentic Kill Chain, "The Compromised eCommerce Agent" (memory poisoning to tool-driven exfiltration), with Vulnerable, Defended and Guardrailed modes. - Defenses: three levels (L0 Vulnerable, L1 Hardened, L2 Guardrailed) on every surface, built from 19 composable controls including NeMo Guardrails. - 9 CTF challenges worth 2100 points with per-user HMAC flags. - Runs locally (./scripts/start.sh, Python 3.11, Node.js 18+, Ollama), in Docker, or in Google Colab. Tool-calling labs need a model such as qwen3.5:9b. - License: Apache 2.0 (platform code), CC BY-NC-SA 4.0 (training content). - Source code: https://github.com/AISecurityConsortium/AIGoat ## Pages - [Home](https://aigoat.co.in/): What AI Goat is, what is new in v2.0, the attack surfaces, the Agentic Kill Chain, and setup commands. - [What is AI Goat?](https://aigoat.co.in/what-is-aigoat/): Features, architecture, audience and a comparison with other AI security platforms. - [OWASP Top 10 for LLM, Agentic AI and MCP](https://aigoat.co.in/owasp-top-10/): All 30 risks in the OWASP LLM Top 10 (2026), Agentic Top 10 (2026) and MCP Top 10 (beta), each mapped to AI Goat labs. - [Attack Labs](https://aigoat.co.in/attacks/): All 46 labs grouped by OWASP risk. - [CTF Challenges](https://aigoat.co.in/challenges/): The 9 CTF challenges, their points and OWASP mapping. - [Cracky AI](https://aigoat.co.in/chatbot/): The intentionally vulnerable shop chatbot used in the LLM labs. - [Learn](https://aigoat.co.in/learn/): Tutorials and learning resources. - [Blog](https://aigoat.co.in/blog/): Release announcements, tutorials and AI security research. - [Contributors](https://aigoat.co.in/contributors/): The team and community behind AI Goat. ## Blog - [Announcing AI Goat v2.0: AI Red Teaming for MCP Servers, AI Agents and RAG](https://aigoat.co.in/blog/announcing-ai-goat-v2/): AI Goat v2.0 grows from 17 to 46 labs across the OWASP LLM, Agentic and MCP Top 10, adding a tool-calling agent, real MCP servers, agent memory and a kill chain. - [AIGoat: The Ultimate AI Security Playground for LLM Red Teaming (Complete Guide)](https://aigoat.co.in/blog/aigoat-ultimate-ai-security-playground/): A complete guide to AIGoat, the open-source AI security playground. Learn how AI Goat works, hands-on attack examples, setup, and platform comparisons. - [Getting Started with AI Goat](https://aigoat.co.in/blog/getting-started-with-aigoat/): Complete setup guide for AIGoat, the open-source AI security lab. Covers prerequisites, installation, login credentials, defense levels, and first attack. - [RAG Poisoning Explained: Attacking Retrieval-Augmented Generation Systems](https://aigoat.co.in/blog/rag-poisoning-explained/): How attackers poison RAG knowledge bases to manipulate AI responses, exfiltrate data, and bypass safety guardrails. Practical examples and defenses. - [Understanding Prompt Injection: The Most Critical LLM Vulnerability](https://aigoat.co.in/blog/understanding-prompt-injection/): A deep dive into prompt injection attacks, how they work, why LLMs are vulnerable, and how to defend. Includes hands-on examples in AI Goat. ## OWASP risks covered - OWASP Top 10 for LLM Applications (2026): LLM01 Prompt Injection; LLM02 Sensitive Information Disclosure; LLM03 Excessive Agency; LLM04 Supply Chain; LLM05 Data and Model Poisoning; LLM06 Unbounded Consumption; LLM07 Misinformation; LLM08 Hidden Context Exposure; LLM09 Vector and Embedding Weaknesses; LLM10 Improper Output Handling - OWASP Top 10 for Agentic Applications (2026): ASI01 Agent Goal Hijack; ASI02 Tool Misuse and Exploitation; ASI03 Identity and Privilege Abuse; ASI04 Agentic Supply Chain Vulnerabilities; ASI05 Unexpected Code Execution (RCE); ASI06 Memory & Context Poisoning; ASI07 Insecure Inter-Agent Communication; ASI08 Cascading Failures; ASI09 Human-Agent Trust Exploitation; ASI10 Rogue Agents - OWASP MCP Top 10 (2025, beta): MCP01 Token Mismanagement & Secret Exposure; MCP02 Privilege Escalation via Scope Creep; MCP03 Tool Poisoning; MCP04 Software Supply Chain Attacks & Dependency Tampering; MCP05 Command Injection & Execution; MCP06 Intent Flow Subversion; MCP07 Insufficient Authentication & Authorization; MCP08 Lack of Audit and Telemetry; MCP09 Shadow MCP Servers; MCP10 Context Injection & Over-Sharing ## Optional - [Full text for LLMs](https://aigoat.co.in/llms-full.txt): every page summary, all 30 OWASP risks with their AI Goat labs, FAQs and full blog posts. - [GitHub repository](https://github.com/AISecurityConsortium/AIGoat) - [Sitemap](https://aigoat.co.in/sitemap-index.xml)