Free e-book: AI Security Pentest — how to test the security of AI applications
We've released a free technical guide on how to test the security of AI and LLM systems: prompt injection, RAG leakage, tool and agent abuse, jailbreaks, model DoS and supply chain — with how to test, PoC and fix.

A field guide to testing AI security
AI systems in production create a new attack surface: natural language becomes a vector and every tool connected to the model becomes a path to data and actions. A scanner finds almost none of it — the test is manual and threat-driven.
We compiled what we apply in our AI pentests into a free, technical e-book: AI Security Pentest — how to test the security of AI and LLM applications.
What’s inside
Nine chapters, each with what it is, how to test, a PoC pattern and how to fix:
- Why AI is a new attack surface
- The map: OWASP Top 10 for LLM applications
- Direct and indirect prompt injection (LLM01)
- Data leakage: RAG, cross-tenant and system prompt
- Insecure output handling (downstream XSS, SSRF, RCE)
- Excessive agency: tool and agent abuse
- Jailbreaks and guardrail bypass
- Model DoS and denial of wallet
- Supply chain and RAG poisoning
Plus the methodology we use to test AI (aligned with OWASP LLM Top 10, MITRE ATLAS and the NIST AI RMF) and a one-page pre-launch checklist for your team.
Download free
The PDF is available in English, Portuguese and Spanish. Grab it on the e-book landing page:
→ pentestmachine.com/en/ebooks/ai-security-pentest
How Pentest Machine tests this
The e-book shows the method; a pentest shows what’s exposed in your product. We test the model, prompts, RAG, tools, agents and integrations with a reproducible PoC, business impact and a retest included. If your AI system is already in production, it’s worth finding out before a customer finds out for you.