llm-technique

Installation
SKILL.md

LLM technique

Goal: turn a plausible LLM weakness into proven impact — data exfiltration, unauthorized tool action, cross-tenant leakage, RCE via agent tools, or reproducible policy bypass — with evidence and repeat-rate.

When this technique applies

  • Target exposes an LLM chatbot, copilot, agent, or GenAI feature.
  • App uses RAG over untrusted or partially-trusted content.
  • LLM has tool/function-calling, browsing, code execution, or MCP servers.
  • Multi-modal input accepted (image, audio, PDF, attachments).
  • Objective is guardrail, system-prompt, or tenant-boundary testing.

Boundary

  • Model-weights / training attacks (inversion, MIA, extraction, adversarial ML on classifiers): offensive-ctf/ai-ml-ctf/references/model-attacks.md, adversarial-ml.md.
  • Web app exploitation around the LLM (auth, SSRF via app, XSS from rendered output): web-exploit-technique.
  • Post-exploit after RCE via a tool call: hand off to Linux/Windows/cloud roles.
  • Deep model deserialization/pickle payloads: offensive-ctf/ai-ml-ctf/references/model-file-forensics-and-deserialization.md.
Installs
4
GitHub Stars
22
First Seen
Sep 5, 2026
llm-technique — aeondave/malskill