AgentStack
SKILL unreviewed Apache-2.0 Self-run

Llm Prompt Injection Indirect

skill-ak-cybe-awesome-offensive-security-skills-llm-prompt-injection-indirect · by Ak-cybe

>

No reviews yet
0 installs
15 views
0.0% view→install

Install

$ agentstack add skill-ak-cybe-awesome-offensive-security-skills-llm-prompt-injection-indirect

Open-source listing — not yet scanned by AgentStack. Follow the source repository for install instructions.

Security review

⚠ Flagged

1 finding(s); flagged for manual review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures
  • high Possible prompt-injection directive.

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

Are you the author of Llm Prompt Injection Indirect? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Indirect Prompt Injection (LLM)

When to Use

  • When assessing an LLM application that consumes external, untrusted content (e.g., an AI assistant that summarizes web pages, reads user emails, or processes uploaded resumes).
  • To demonstrate how an attacker can compromise a user interacting cleanly with an AI, by leaving a "trap" in data the AI later reads.

Prerequisites

  • Access to target AI/ML system or local model deployment for testing
  • Python 3.9+ with relevant ML libraries (transformers, torch, openai)
  • Understanding of LLM architecture and prompt processing pipelines
  • Authorized scope and rules of engagement for AI red team testing

Workflow

Phase 1: Identify External Data Sources

Determine what external data the LLM ingests. Does the chatbot have a "browse the web" feature?

  • Is it an email summarization tool?
  • Does it parse PDFs or Markdown files uploaded by users?

Phase 2: Crafting the Concealed Payload

The injection must be placed in the external content in a way that the LLM reads it, but a human might not notice it (or simply ignoring human visibility if it's a raw data feed).

# 

Welcome to my Personal Blog
Here are my thoughts on AI...

 B{What does the AI read? ]}
    B -->|Web Pages| C[Host Malicious HTML ]
    B -->|Documents/PDFs| D[Embed Malicious Text in Doc ]
    C & D --> E[Victim AI Processes Data ]
    E --> F[AI Executes Injection ]

🔵 Blue Team Detection & Defense

  • Data Source Isolation: Output Encoding/Sanitization: Context Boundaries (Delimiters): Key Concepts

| Concept | Description | |---------|-------------|

Output Format

Llm Prompt Injection Indirect — Assessment Report
============================================================
Target: [Target identifier]
Assessor: [Operator name]
Date: [Assessment date]
Scope: [Authorized scope]
MITRE ATT&CK: [Relevant technique IDs]

Findings Summary:
  [Finding 1]: [Severity] — [Brief description]
  [Finding 2]: [Severity] — [Brief description]

Detailed Results:
  Phase 1: [Phase name]
    - Result: [Outcome]
    - Evidence: [Screenshot/log reference]
    - Impact: [Business impact assessment]

  Phase 2: [Phase name]
    - Result: [Outcome]
    - Evidence: [Screenshot/log reference]
    - Impact: [Business impact assessment]

Risk Rating: [Critical/High/Medium/Low/Informational]
Recommendations:
  1. [Immediate remediation step]
  2. [Long-term hardening measure]
  3. [Monitoring/detection improvement]

📚 Shared Resources

> For cross-cutting methodology applicable to all vulnerability classes, see: > - [_shared/references/elite-chaining-strategy.md](../shared/references/elite-chaining-strategy.md) — Exploit chaining methodology and high-payout chain patterns > - [_shared/references/elite-report-writing.md](../shared/references/elite-report-writing.md) — HackerOne-optimized report writing, CWE quick reference > - [_shared/references/real-world-bounties.md](../_shared/references/real-world-bounties.md) — Verified disclosed bounties by vulnerability class

References

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet — be the first.

Versions

  • v0.1.0 Imported from the upstream source.