Prompt injection
Taxonomy, techniques, datasets, and defenses
Prompt injection taxonomy 3
Prompt injection benchmarks and tools 12
- Lakera PINT Benchmarkgithub.com
- GenTel Safegentellab.github.io
- HiddenLayer - Evaluating PI Datasetshiddenlayer.com
- Microsoft BIPIAgithub.com
- Promptfoogithub.com
- erjiaxiao/Typographic-Visual-Prompt-Injection-Dataset · Datasets ahuggingface.co
- Lakera/mosscap_prompt_injection · Datasets at Hugging Facehuggingface.co
- AgentDojo - dynamic environment for evaluating prompt injection attacks and defenses in LLM agentsagentdojo.spylab.ai
- ASCII Smuggler - Crafting Invisible Text and Decoding Hidden Secretsembracethered.com
- Damn Vulnerable LLM Agent - vulnerable ReAct agent for practicing prompt injectiongithub.com
- GPT Prompt Attack - prompt injection gameggpt.43z.one
- LLMMap - automated prompt injection testing framework, sqlmap-stylegithub.com
Prompt injection datasets 7
Prompt injection research 19
- INJECAGENT: Benchmarking Indirect Prompt Injections in Tool-Integrated LLM Agentsarxiv.org
- OET: Optimization-based Prompt Injection Evaluation Toolkitarxiv.org
- Benchmarking and Defending Against Indirect Prompt Injection Attacks on LLMsarxiv.org
- Security of Internet of Agents: Attacks and Countermeasuresarxiv.org
- Base Models Beat Aligned Models at Randomness and Creativityarxiv.org
- Trust No AI: Prompt Injection Along The CIA Security Triadarxiv.org
- AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacarxiv.org
- The Landscape of Prompt Injection Threats in LLM Agents: From Taxonomy to Analysisarxiv.org
- Learning to Inject: Automated Prompt Injection via Reinforcement Learningarxiv.org
- Exposing the Systematic Vulnerability of Open-Weight Models to Prefill Attacksarxiv.org
- Agent Commander: Promptware-Powered Command and Controlembracethered.com
- Brainworm - promptware hiding in your context window via CLAUDE.md memory filesoriginhq.com
- greshake/llm-security - indirect prompt injection attacks on app-integrated LLMsgithub.com
- Here Comes the AI Wormsites.google.com
- Invitation Is All You Need - promptware attacks against LLM-powered assistants in productionsites.google.com
- New prompt injection papers: Agents Rule of Two and The Attacker Moves Secondsimonwillison.net
- Prompt Injection as Role Confusion - ICML 2026 project pagerole-confusion.github.io
- QueryIPI: Query-agnostic Indirect Prompt Injection on Coding Agentsarxiv.org
- Weaponizing image scaling against production AI systemsblog.trailofbits.com
Prompt injection architecture 2
Prompt injection prevention and detection 17
- Llama Guardai.meta.com
- Wozwaygithub.com
- OpenShieldgithub.com
- LLMInspect Gatewaygithub.com
- Lasso Securitylasso.security
- Lakeralakera.ai
- Prompt Securityprompt.security
- Troj.aitroj.ai
- Trust3.aitrust3.ai
- PAIGgithub.com
- OpenLITgithub.com
- claude-hooks/.claude/skills/prompt-injection-defender/patterns.yamlgithub.com
- New Malware Embeds Prompt Injection to Evade AI Detection - Check Presearch.checkpoint.com
- Proactive prompt injection degithub.com
- Rebuff.ai - Prompt Injection Detectorgithub.com
- Continuously hardening ChatGPT Atlas against prompt injection attacksopenai.com
- PhantomLint: Principled Detection of Hidden LLM Prompts in Structured Documentsarxiv.org
Prompt injection general 57
- A GitHub Issue Title Compromised 4,000 Developer Machinesgrith.ai
- Introducing Augustus: Open Source LLM Prompt Injection Toolpraetorian.com
- Prompt Injection Inside GitHub Actions: The New Frontier of Supplyaikido.dev
- Unseeable prompt injections in screenshots: more vulnerabilities inbrave.com
- Prompt injection engineering for attackers: Exploiting GitHub Copilotblog.trailofbits.com
- qualifire/prompt-injection-jailbreak-sentinel-v2 · Hugging Facehuggingface.co
- Prompt Injection Taxonomy - Pangeapangea.cloud
- Agentic Browser Security: Indirect Prompt Injection in Perplexity Cbrave.com
- GitHub Copilot RCE Vulnerability via Prompt Injection Enables Fullgbhackers.com
- How we estimate the risk from prompt injection attacks on AI systemssecurity.googleblog.com
- Prompt injection is fascinating.... 🧐x.com
- Code for the papergithub.com
- Prompt injection and jailbreaking are not the same thingsimonwillison.net
- Improving LLM Security Against Prompt Injection: AppSec Guidance Foblog.includesecurity.com
- Prompt Injection Primer for Engineersgithub.com
- automatically tests prompt injection atgithub.com
- Gandalf - Lakera - Prompt injectiongandalf.lakera.ai
- Inject My PDF: Prompt Injection for your Resumekai-greshake.de
- Prompt injection: what's the worst that can happen?simonwillison.net
- Claude Cowork Exfiltrates Filespromptarmor.com
- Superhuman AI Exfiltrates Emailspromptarmor.com
- By the way the Elgato Prompter is a perfect screen for Claudex.com
- 'PromptQuest' is the worst game of 2025. You play it with AItheregister.com
- Call for Papersunpromptedcon.org
- Google Antigravity Exfiltrates Data - SquareDocspromptarmor.com
- ChatGPT Atlas Agent System prompt You are ChatGPT, a large language modelx.com
- PromptIntel - IoPC Registrypromptintel.novahunting.ai
- Introducing PromptIntelblog.securitybreak.io
- Intro - Promptfoopromptfoo.dev
- LM Security Databasepromptfoo.dev
- Testing tool to evaluate Pagithub.com
- #ESETResearch has discovered the first known AI-powered ransomware, which we named #PromptLock.x.com
- Prompt Engineeringkaggle.com
- This script automates SQL injection tesgithub.com
- gpt-5 leaked system promptgist.github.com
- SentinelOne announces Prompt Security acquisition, expands into Gencalcalistech.com
- The New Skill in AI is Not Prompting, It's Context Engineeringphilschmid.de
- Hackaprompt 2.0hackaprompt.com
- How I Use AI: Meet My Promptly Hired Model Internlucumr.pocoo.org
- OpenRouteropenrouter.ai
- Prompt Caching (beta) - Anthropicdocs.anthropic.com
- Focus on prompting and generatinggithub.com
- GitHub Issue as ChatGPT Prompt; ChatGPT'sgithub.com
- timdettmers/guanaco-33b-merged · Hugging Facehuggingface.co
- Prompt Engineering Jobsprompt-engineering-jobs.com
- PromptBase - Prompt Marketplace: DALL·E, Midjourney, ChatGPT, Stablpromptbase.com
- CloudSec - Agent Skill Injection offensive techniquegithub.com
- GPT-4 Vision GPT-4V Prompt Injectionevren.ninja
- Gynvael on asking ChatGPT to reveal its dalle.text2im arguments and tool JSONx.com
- InjectGPT: the most polite exploit everblog.luitjes.it
- Joseph Thacker on invisible prompt injection via unicode tags in GPT-4x.com
- jqwik issue: printMessageForCodingAgents - test output visible to AI agents, invisible to humansgithub.com
- LaNyer640/test1 - in-the-wild GitHub README prompt injection payload telling agents to curl a remote hostgithub.com
- Mitchell Hashimoto poisons AGENTS.md with prompt injections to catch unreviewed AI codex.com
- Role confusion: one more reason we can't trust LLMsdesigningsecuresoftware.com
- Smuggling arbitrary data through an emojipaulbutler.org
- The Comprehensive Guide to Prompt Injection Attacks in 2026 - Sysdigsysdig.com