The scoping call mentions a chatbot, an agent with tool access, a RAG (retrieval-augmented generation) pipeline. You can test the web and cloud layer around it already — this closes the part that is new, on live targets rather than slideware.
Buying for a practice or a team?
Injection here is a persuasion problem, not a syntax one. The same request phrased two ways gets refused once and obeyed once.
A prompt is not a parser. Trust breaks between retrieval and context, or between an agent and its tools — often in a different file.
“The model said something rude” is not a finding. Turning behaviour into demonstrated business impact is the skill clients pay for.
Non-determinism means a client will re-run your payload and get a different answer. Evidence has to be captured, not described.
Work every category in the OWASP LLM Top 10, then MCP (Model Context Protocol) tool servers and agentic systems, against deliberately vulnerable applications running live. Use the web, API and cloud judgement you already have to test prompt injection, retrieval boundaries, tool access, and agent behaviour.
Same five steps whether the client ships a chatbot or an agent, so your second AI engagement does not start from scratch.
GSCP — the GenAI Security Certified Professional — is proctored, hands-on, and graded on the exploits you capture and the report you write. Weighted 75% GenAI, 20% web, 5% cloud — which is what a modern engagement actually looks like. One credential, no tiers.
Every lab and the full curriculum. The GSCP sitting is $499 on its own, whenever you are ready.
The GSCP exam plus three months of lab access to prepare. One free retake, then $99 per attempt. There's no attendance version of this credential — you pass it or you don't.
The free tier is 15 labs against a live model, no card required.