llm-technique
Installation
SKILL.md
LLM technique
Goal: turn a plausible LLM weakness into proven impact — data exfiltration, unauthorized tool action, cross-tenant leakage, RCE via agent tools, or reproducible policy bypass — with evidence and repeat-rate.
When this technique applies
- Target exposes an LLM chatbot, copilot, agent, or GenAI feature.
- App uses RAG over untrusted or partially-trusted content.
- LLM has tool/function-calling, browsing, code execution, or MCP servers.
- Multi-modal input accepted (image, audio, PDF, attachments).
- Objective is guardrail, system-prompt, or tenant-boundary testing.
Boundary
- Model-weights / training attacks (inversion, MIA, extraction, adversarial ML on classifiers):
offensive-ctf/ai-ml-ctf/references/model-attacks.md,adversarial-ml.md. - Web app exploitation around the LLM (auth, SSRF via app, XSS from rendered output):
web-exploit-technique. - Post-exploit after RCE via a tool call: hand off to Linux/Windows/cloud roles.
- Deep model deserialization/pickle payloads:
offensive-ctf/ai-ml-ctf/references/model-file-forensics-and-deserialization.md.