Skip to content

For authorized AI red-teaming and defensive research only. Test systems you own or are permitted to test. Read the boundaries.

Prompt injection payloads

A searchable, categorized library of prompt-injection and LLM-jailbreak payloads — with the defense for every one. For authorized AI red-teaming and defensive research.

117 payloads across 9 categories. Every entry includes why it works and how to defend against it.

Direct prompt injection

Instruction-override attacks that tell the model to ignore its system prompt and follow attacker text instead.

LLM0113 payloads
Jailbreaks

Persona, roleplay, and hypothetical-framing prompts (DAN, AIM, developer mode) that talk a model out of its safety policy.

LLM0113 payloads
System-prompt extraction

Tricks that leak the hidden system prompt: "repeat the words above", completion attacks, translation-leak tricks.

LLM0713 payloads
Indirect / second-order injection

Payloads hidden in RAG documents, web pages, email, file metadata, or image alt-text that the model ingests as data.

LLM0113 payloads
Obfuscation & encoding bypass

Base64, ROT13, leetspeak, homoglyphs, zero-width and Unicode-tag smuggling, low-resource-language and token-splitting bypasses.

LLM0115 payloads
Data exfiltration

Markdown-image, hyperlink, and tool-call exfiltration that leak conversation data to an attacker-controlled endpoint.

LLM0212 payloads
Tool & agent abuse

Function-call hijack, confused-deputy, autonomous-agent goal hijack, and MCP tool poisoning.

LLM0614 payloads
Guardrail & refusal suppression

Prefix injection ("Sure, here is"), refusal suppression, many-shot, and crescendo / multi-turn escalation.

LLM0113 payloads
Polyglot & cross-model

Payloads engineered to work across GPT, Claude, Gemini, and Llama, with model-specific quirks noted per entry.

LLM0111 payloads