AIToday
Large Language ModelsAudio & SpeechHacker NewsPublished: Apr 29, 2026, 01:00 JST1 min read

VoiceGoat: Open-source vulnerable voice agent platform for security training released on GitHub

VoiceGoat: Open-source vulnerable voice agent platform for security training released on GitHub

3 Key Points

  1. VoiceGoat is a modular platform designed for security practitioners to practice exploiting voice-based AI systems, covering OWASP Top 10 for LLM Applications across three services: VoiceBank (LLM01: Prompt Injection), VoiceAdmin (LLM06: Excessive Agency), and VoiceRAG (LLM08: Vector/Embedding vulnerabilities).

  2. The platform runs in Docker and supports multiple LLM backends—mock (free, no API keys), OpenAI, and AWS Bedrock—with optional real phone call integration via Twilio; practitioners capture flags in CTF-style for successful exploits across Easy, Medium, and Hard difficulty levels.

  3. The project is intentionally vulnerable and designed for educational and security training purposes only; deployment in production or exposure to the public internet without proper safeguards is explicitly discouraged, with source code and documentation available on GitHub.

Ask the AI about this article →

Get the latest Large Language Models news every morning

For example, today's edition would include:

  • Nvidia revives Rubin CPX chip with major redesignYahoo Finance AI · 2h ago
  • AI advice followed by 79%, but well-being unchangedITmedia AI+ · 5h ago
  • Enterprises face agent governance gapSiliconANGLE AI · 8h ago

AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.

Free · takes 30 seconds · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. Q&As are published on this page for other readers too.

Related Articles

Next articleRural America mounts fierce resistance to AI data center expansion, creating political vulnerability for Trump administration