1
2 Comments

Sharing a few LLM security resources we built while testing AI APIs

We've been working on PromptBrake — an automated scanner that runs security tests against LLM-powered API endpoints. Along the way, we ended up building a few standalone tools that might be useful even outside of it:

  • LLM Security Checklist Builder — a practical release checklist covering prompt injection, tool permissions, data exposure, and output controls

  • Prompt Injection Payload Generator — generates direct, indirect, and multi-turn injection payloads you can adapt for testing your own endpoint

  • OWASP LLM Test Case Mapper — translates OWASP LLM Top 10 risks into concrete test ideas with ownership guidance

All three are free and don't require an account: promptbrake.com/free-tools

We built these to give back to the community that's been sharing knowledge in this space. LLM security is still early, and a lot of teams aren't sure what they might be missing — figured it's better to make this kind of stuff accessible rather than gate it.

Curious how others here are approaching this — do you have a repeatable process before shipping LLM features, or is it still mostly ad hoc?

posted to Icon for group Application Security
Application Security
on April 22, 2026
  1. 1

    The Prompt Injection Payload Generator is a massive gift to the dev community, Specialist-Bee9801. Most teams are still in the "ad-hoc" phase of AI safety; by mapping concrete test cases to the OWASP Top 10, you’re turning vague "AI anxiety" into a repeatable technical workflow.

    I’m currently running Tokyo Lore, a project that highlights high-utility security tools and the logic behind them. Since you're building the infrastructure to protect LLM-powered APIs from injection and data exposure, entering PromptBrake could be the perfect way to get your scanners in front of more engineering teams while your odds are at their absolute peak.

    1. 1

      Appreciate the kind words — glad the tools are useful. Right now, we’re focused on building and improving things based on direct user feedback, but thanks for reaching out

Trending on Indie Hackers
Agencies charge $5,000 for a 60-second product demo video. I make mine for $0. Here's the exact workflow. User Avatar 126 comments I wasted 6 months building a failed startup. Built TrendyRevenue to validate ideas in 10 seconds. User Avatar 55 comments I've been building for months and made $0. Here's the honest psychological reason — and it's not what I expected. User Avatar 51 comments Your files aren’t messy. They’re just stuck in the wrong system. User Avatar 28 comments Why Direction Matters More Than Motivation in Exam Preparation User Avatar 14 comments I built a health platform for my family because nobody has a clue what is going on User Avatar 13 comments