What problem does it solve?
This Skill solves the common pain point of wasting time on confabulated false positives when testing LLM/AI features, providing a structured validation framework to identify only exploitable vulnerabilities that cross trust boundaries and meet professional reporting standards.
Core Features & Use Cases
- Comprehensive LLM Bug Coverage: Tests for direct/indirect prompt injection, markdown/tool-use exfiltration, ASCII smuggling, system prompt leakage, IDOR via AI data layers, RAG poisoning, and OWASP Agentic Applications (ASI01-ASI10) flaws.
- False Positive Elimination: Includes a 5-point validation gate requiring out-of-band callbacks, run-twice reproducibility, anchored leaks, and verifiable cross-tenant artifacts to avoid reporting confabulation or non-exploitable model behavior.
- Use Case: Use during penetration tests of LLM-backed chatbots, RAG systems, agentic copilots, MCP tools, and AI-powered security scanners to find high-impact, reportable vulnerabilities instead of low-value informational findings.
Quick Start
Use the hunt-llm-ai skill to test the target's LLM-powered chatbot and related AI features for exploitable prompt injection and exfiltration vulnerabilities, validating all findings with out-of-band callbacks to avoid false positives.