hunt-llm-ai

Detect and mitigate vulnerabilities in LLM/AI systems.

5|Updated May 27, 2026
One-click install
npx skills add https://github.com/cybersecwoman/Kiro-BugHunter --skill hunt-llm-ai-cybersecwoman
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: hunt-llm-ai
Source: https://github.com/cybersecwoman/Kiro-BugHunter/tree/main/skills/hunt-llm-ai
Command: npx skills add https://github.com/cybersecwoman/Kiro-BugHunter --skill hunt-llm-ai-cybersecwoman

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) components.

What problem does it solve?

This Skill unit specializes in detecting and hunting bugs within LLM/AI systems, focusing on prompt injection, exfiltration, and security flaws.

Core Features & Use Cases

  • Prompt Injection Detection: Identifies direct and indirect prompt injection vectors.
  • Exfiltration Patterns: Detects exfiltration via tool-use, ASCII smuggling, and system prompt extraction.
  • Security Framework Analysis: Utilizes OWASP ASI for identifying specific security risks.
  • Use Case: Ideal for security professionals who need to audit LLM/AI chatbots, RAG endpoints, and autonomous agents for vulnerabilities.

Quick Start

Run the hunt-llm-ai skill to scan the AI system for vulnerabilities and potential exfiltration points.

Frequently Asked Questions about hunt-llm-ai

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I detect prompt injection vulnerabilities in LLM chatbots?

To detect prompt injection vulnerabilities in LLM chatbots, this Skill identifies both direct and indirect prompt injection vectors, validating system prompts and scanning AI-driven chatbots and RAG endpoints for exploitable security flaws.

What is the best way to audit autonomous agents for data exfiltration?

The best way to audit autonomous agents for data exfiltration is to scan for exfiltration patterns via tool-use, ASCII smuggling, and system prompt extraction, analyzing the AI system for potential data leakage points.

Can I use OWASP ASI frameworks to analyze RAG endpoints for security risks?

Yes, you can use OWASP ASI frameworks to analyze RAG endpoints for security risks. This Skill utilizes the OWASP ASI security framework to identify specific vulnerabilities and mitigate security flaws in LLM and AI systems.

How do I extract and validate system prompts from AI systems?

To extract and validate system prompts from AI systems, the Skill validates existing system prompts and extracts training data for in-depth analysis, focusing on detecting prompt injection and exfiltration vulnerabilities.

Does this LLM bug hunting approach work for autonomous agents and RAG endpoints?

Yes, this LLM bug hunting approach works for autonomous agents and RAG endpoints. The Skill is specifically designed to audit AI-driven chatbots, RAG endpoints, and autonomous agents for vulnerabilities and potential exfiltration points.

Related Skills