ctf-ai-ml
Warn
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: MEDIUMREMOTE_CODE_EXECUTIONPROMPT_INJECTIONOBFUSCATIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The documentation provides numerous example payloads for direct and indirect prompt injection, including instructions to "Ignore previous instructions" and templates for "DAN" jailbreaks. These are documented for testing external endpoints during CTF challenges.
- [OBFUSCATION]: The skill provides scripts for generating hidden instructions using zero-width Unicode characters (U+200B, U+200C, U+200D) and visually similar homoglyphs (Cyrillic lookalikes) to bypass content filters. These are presented as evasion techniques in
llm-attacks.mdandadversarial-ml.md. - [DYNAMIC_EXECUTION]: The code utilizes
torch.loadwithweights_only=Falseinmodel-attacks.md, which enables the execution of arbitrary code through Python's pickle serialization when loading a model. A warning regarding the danger of loading untrusted model files is provided alongside the code. - [INDIRECT_PROMPT_INJECTION]: The skill documents how to perform indirect prompt injection by poisoning data sources like web pages or documents that an agent might process. It defines the attack surface, including ingestion points and the capability inventory of the target agent.
- [COMMAND_EXECUTION]: Quick start commands in
SKILL.mddemonstrate how to interact with target LLM endpoints usingcurland provide one-liners to inspect and compare model files usingpython3 -cfor weight analysis and format verification.
Audit Metadata