2
2 Comments

Sharing a few LLM security resources we built while testing AI APIs

We've been working on PromptBrake — an automated scanner that runs security tests against LLM-powered API endpoints. Along the way, we ended up building a few standalone tools that might be useful even outside of it:

  • LLM Security Checklist Builder — a practical release checklist covering prompt injection, tool permissions, data exposure, and output controls

  • Prompt Injection Payload Generator — generates direct, indirect, and multi-turn injection payloads you can adapt for testing your own endpoint

  • OWASP LLM Test Case Mapper — translates OWASP LLM Top 10 risks into concrete test ideas with ownership guidance

All three are free and don't require an account: promptbrake.com/free-tools

We built these to give back to the community that's been sharing knowledge in this space. LLM security is still early, and a lot of teams aren't sure what they might be missing — figured it's better to make this kind of stuff accessible rather than gate it.

Curious how others here are approaching this — do you have a repeatable process before shipping LLM features, or is it still mostly ad hoc?

posted to Icon for group Building in Public
Building in Public
on April 22, 2026
  1. 1

    Providing a "Prompt Injection Payload Generator" is a massive service to the dev community, as most teams are still in the "ad-hoc" phase of LLM security. By mapping concrete test cases to OWASP Top 10 risks, you're turning vague AI anxiety into a repeatable technical workflow.
    I’m currently running a project in Tokyo (Tokyo Lore) that highlights high-utility security tools and the logic behind them. Since you're building the infrastructure to protect LLM-powered APIs from injection and data exposure, entering your project could be the perfect way to get your scanners in front of more engineering teams while your odds are at their absolute peak.

  2. 1

    Smart move making the education layer free.
    In emerging markets, trust is often built faster through useful tools than through direct product pitches.

Trending on Indie Hackers
I launched on Product Hunt today with 0 followers, 0 network, and 0 users. Here's what I learned in 12 hours. User Avatar 127 comments The most underrated distribution channel in SaaS is hiding in your browser toolbar User Avatar 110 comments I gave 7 AI agents $100 each to build a startup. Here's what happened on Day 1. User Avatar 73 comments A simple LinkedIn prospecting trick that improved our lead quality User Avatar 60 comments Show IH: RetryFix - Automatically recover failed Stripe payments and earn 10% on everything we win back User Avatar 32 comments How we got our first US sale in 2 hours by finding "Trust Leaks" (Free Audits) 🌶️ User Avatar 23 comments