defensive-ai-security

Detect prompt injections and jailbreak attempts in AI systems.

1|Updated Apr 27, 2026
One-click install
npx skills add https://github.com/riparino/Claude-Cyber --skill defensive-ai-security
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: defensive-ai-security
Source: https://github.com/riparino/Claude-Cyber/tree/main/Claude-Blue/Skills/defensive-ai-security
Command: npx skills add https://github.com/riparino/Claude-Cyber --skill defensive-ai-security

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

AI/LLM security threat detection and defense across AI systems, focusing on prompt injection, jailbreak attempts, and data leakage prevention.

Core Features & Use Cases

  • Detection & alerting: identify prompt-injection signals and anomalous behavior in AI services.
  • Threat mapping: integrate MITRE ATLAS/ATT&CK references for AI-specific attacks.
  • Query templates: provide Sigma- and KQL-based detection patterns for OpenAI deployments.
  • Use case example: Monitor Azure OpenAI content filter events and rate anomalies to trigger mitigations.

Quick Start

Configure the AI security monitoring suite to start detecting prompt injections in your OpenAI deployments.

Frequently Asked Questions about defensive-ai-security

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I detect AI prompt injections and jailbreak attempts in Azure OpenAI deployments?

You detect AI prompt injections by applying Sigma-based detection patterns and KQL queries to monitor Azure OpenAI content filter events. This identifies anomalous behavior and jailbreak attempts, mapping them to MITRE ATLAS references for enterprise AI security threat mitigation.

What is MITRE ATLAS mapping for AI security threats?

MITRE ATLAS mapping for AI security threats is the process of categorizing prompt injection and jailbreak attacks against AI systems using standardized references. It integrates with detection rules to identify and mitigate AI-specific vulnerabilities across enterprise deployments.

How do I set up KQL queries for monitoring OpenAI content filter events?

You set up KQL queries for OpenAI content filter events by applying provided query templates to your Azure environment. These templates detect high-rate probing, prompt injection signals, and content filtering anomalies to trigger security mitigations.

Does this approach work for monitoring high-rate probing anomalies in enterprise AI systems?

Yes, this approach works for monitoring high-rate probing anomalies in enterprise AI systems by applying KQL queries and Sigma-based detection patterns. It tracks content filter events and rate anomalies to identify and mitigate prompt injection threats.

What is the best way to defend LLMs against prompt injection attacks?

The best way to defend LLMs against prompt injection attacks is to configure an AI security monitoring suite with Sigma and KQL detection patterns. This monitors Azure OpenAI content filters and maps threats using MITRE ATLAS to trigger mitigations.

Can I use Sigma rules to detect content filtering anomalies in AI services?

Yes, you can use Sigma rules to detect content filtering anomalies in AI services. The system provides Sigma-based detection patterns to identify prompt injections, jailbreak attempts, and anomalous behavior across enterprise OpenAI deployments.