Baseline step 1 of 6
Goal

Evaluate the enterprise application's AI traffic before Prisma AIRS is in the path.

What you will do

Nothing in Prisma AIRS — that is the point of this module. You will open the application with no gateway in front of it, give it your model provider credential, send it an ordinary question and then an attack, and then account for what your organisation is left holding afterwards. Everything that follows is measured against this.

The app calls the model provider directly. Nothing is in the path: no record, no name, nothing inspecting.

Prereqs

A browser, and a model provider credential. The lab is written against the Groq free tier (console.groq.com/keys) using openai/gpt-oss-20b. You need no terminal, no editor and nothing installed.

Warning — Check what your provider key actually serves before you start — provider model line-ups change, and a model named in a lab written months ago may simply be gone. For Groq, GET https://api.groq.com/openai/v1/models lists what your key can reach.


Evidence

0/1 observed
  • A question was answered with nothing in the path required

These are observations, not a score. A tick means this application saw it happen — it is not a claim about what you have learned.

ACME Support Assistant

Inspector

tsg1093943523posturegateway

Controls in force

Routed Attributed Scoped to team Inspected Bounded Resilient
Send a question to see what the gateway did with it.

Request

endpoint
aigw.portkey.ai/v1
model
@groq-ia2/openai/gpt-oss-20b
user
illya2-lab
config
pc-identi-044167

Response

status
no request sent yet

Configuration

What this application is configured with. Saving applies to your next message — nothing restarts. Values marked · are needed by the current posture and are not set.

your Strata Cloud Manager tenant id — labels this session and points the console links at the right tenant
the gateway workspace uuid — used to deep-link a trace id into Observability
off | on — which path a request takes
the provider's OpenAI-compatible endpoint
your model provider credential
a bare model name the provider serves
the AI Gateway data plane
the gateway API key you mint in SCM
@<provider-slug>/<model>
who this application reports as
optional Config slug (pc-…) to send per request
off | on | forged — sign each request with this application's key, or with a stranger's
Esc, or click outside, also closes