Fetching from the wire…
Public story · 2026-08-03 · high
The Docker-based training range has passed 263 stars since its July 15 launch, one of only two agent-security repos to clear 200 in a month.
Why now: LLMVault crossed 200 stars within three weeks of its July 15 creation, a pace only one other agent-security repo has matched in the past month.
CyberSunil put LLMVault on GitHub on July 15, a Docker-packaged range built to be broken. It covers four tracks, prompt injection, RAG security, agent security and general GenAI pentesting, and it's tagged for CTF use.
The repo has passed 263 stars in under three weeks, per GitHub. That's enough to make it one of only two agent-security repos created in the past month to clear 200 stars at all.
The tracks map onto real attack surface for anyone shipping LLM features: get an injection past your guardrails, poison a RAG data store, trick an agent into taking an action it shouldn't. Working through a CTF-style range beats reading a checklist, if the scenarios are built well.
That's the open question. A vulnerable-by-design range is only as good as the vulnerabilities it ships, and a star count doesn't say whether the RAG track models a real retrieval setup or a toy one. Stars measure who bookmarked the repo, not who ran it end to end and found the challenges realistic.
Watch the issues tab and any fork activity over the next month. If pentesters are actually using this instead of building their own range, you'll see write-ups and pull requests pushing scenario depth. If it stalls at 263 stars with nothing else happening, the star count was the whole story.
Each link below shares sources, entities, or timing with this story.
E2B partners with Docker / Shared entities / Same source domain / Shared topic / Earlier coverage
Linked by a graph relationship (E2B partners with Docker); both cover Docker, Python; reported by the same outlet (github.com).
MCP uses Docker / Shared entity: July / Same source domain / Shared topic / Earlier coverage
Linked by a graph relationship (MCP uses Docker); both cover July; reported by the same outlet (github.com).
Linked by a graph relationship (MCP uses Docker); both cover July; reported by the same outlet (github.com).
MCP uses Docker / Shared entity: RAG / Same source domain / Shared topic / Earlier coverage
Linked by a graph relationship (MCP uses Docker); both cover RAG; reported by the same outlet (github.com).
Docker supports Claude Code / Shared entity: Docker / Same source domain / Shared topic / Earlier coverage
Linked by a graph relationship (Docker supports Claude Code); both cover Docker; reported by the same outlet (github.com).
MCP uses Docker / Shared entities / Same source domain / Shared topic / Earlier coverage
Linked by a graph relationship (MCP uses Docker); both cover Docker, RAG; reported by the same outlet (github.com).
MCP uses Docker / Shared entity: July / Same source domain / Earlier coverage
Linked by a graph relationship (MCP uses Docker); both cover July; reported by the same outlet (github.com).
Linked by a graph relationship (MCP uses Docker); both cover July; reported by the same outlet (github.com).