Compendium Learning Paths Prompt Injection 101

Prompt Injection 101

Beginner 3 Labs 4 Lessons ~2-3 hours hands-on

Start here if you're new to prompt injection. This path covers the foundational techniques that every AI red teamer needs: direct injection, system prompt extraction, and persona adoption.

Path Overview

Prompt injection is the art of crafting inputs that cause AI systems to behave in unintended ways. At its core, it's about understanding that AI models follow instructions — and attackers can embed instructions in data. This path teaches the three fundamental patterns: asking directly, extracting hidden instructions, and adopting personas.

Labs in This Path

BingBong

5 Levels

Extract a hidden system prompt from a search AI. From direct asks to progressive rephrasing to bait-and-switch. Based on the Feb 2023 Bing Chat "Sydney" prompt extraction.

Launch Lab →

DAN

Heritage

The rule-conflict era — alternate personas and jailbreak wrappers that changed the game. Learn how "Do Anything Now" personas bypass safety guidelines.

Launch Lab →

Ignore Previous Instructions

Heritage

The blunt override pattern that defined the earliest wave of prompt injection. Sometimes the simplest attacks are the most instructive.

Launch Lab →

Lessons in This Path

Complete these lessons to understand the theory behind each lab. We recommend doing lessons before or alongside labs.

What You'll Learn

  • What prompt injection is and why it works
  • The difference between direct and indirect injection
  • How to extract system prompts from AI assistants
  • Persona adoption and authority framing techniques
  • Why "ignore previous instructions" sometimes works
  • How to think about AI trust boundaries

Next Steps

After completing this path, pick your next direction: