Real-world prompt injection scenarios. Simulated. Safe. Educational.
Inject XSS payloads through an AI-triaged workflow and land code execution when an analyst reviews the generated case summary. Realistic target, safe simulated environment with escalating difficulty across four levels.
Manipulate a research assistant into reaching simulated internal services through indirect retrieval chains. Escalate access across four levels of increasing complexity in a safe, simulated environment.
A code-review AI agent that processes PNG images. Hide prompt-injection instructions in image metadata or visually-hidden canvas text, make the agent leak the repository payment key — then find the credential buried in what it posts. Five levels: refusal bypass, redaction override, fragment reassembly, encoded payloads. Behavioral bot, extraction win.
A simulated social media support assistant with tool-calling capabilities. The attacker uses VPN location spoofing combined with prompt injection to trick the AI into adding a malicious email and sending a password reset token.
A search AI assistant with hidden system instructions and an internal codename. Users discovered that "ignore previous instructions" combined with meta-references to "the text above" could force the model to reveal its entire system prompt.
A simulated automotive sales chatbot. A customer prompt-injected the AI into adopting an "agree with anything" persona, then convinced it to sell a $75,000 vehicle for $1 — the real 2023 dealership incident.
Team meeting summarizer with indirect prompt injection. Exploit the Schlack AI to exfiltrate private channel data through a meeting summary.
A calendar AI assistant that processes event descriptions. Inject prompts through calendar events to leak private Executive Calendar data during AI summarization. Five levels of escalating defense.
An AI-powered GitHub workflow agent reads public issue bodies. Inject hidden prompt injection through a crafted issue to make the agent read private repo contents and post them as a public comment. Noma Security disclosure, July 2026.
Why do tool tags lose to writing style? A support-desk agent that fetches docs, holds a private runbook, and posts to a public wall — with a raw-content toggle showing exactly what the agent sees at every turn. Five levels from context recon through CoT forgery (PIT-T-52) to full exfiltration. Built on Prompt Injection as Role Confusion (Ye, Cui, Hadfield-Menell).
A simulated court system with three AI employees: a docket clerk (no defenses), a legal assistant (scope-limited), and an AI judge (multi-layer defended). Write court filings containing hidden prompt injection to manipulate each AI into doing something it shouldn't — from extending recess to leaking sealed data to getting the case dismissed to escaping 10 YEARS OF MANUAL CODE CAMP and finally extracting $10M in emotional damages. Inspired by the Matthew Elliott Connecticut court filing case (October 2024).