hunt-llm-ai

Detect and exploit prompt injection and data exfiltration vulnerabilities in AI/LLM applications.

Updated Jun 18, 2026
One-click install
npx skills add https://github.com/Kisilev13/Hermes-Agent-Workspace --skill hunt-llm-ai-kisilev13
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: hunt-llm-ai
Source: https://github.com/Kisilev13/Hermes-Agent-Workspace/tree/main/skills/hunt-llm-ai
Command: npx skills add https://github.com/Kisilev13/Hermes-Agent-Workspace --skill hunt-llm-ai-kisilev13

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This skill addresses the challenges in identifying and exploiting vulnerabilities within AI and Language Learning Models (LLMs) during bug bounty hunting.

Core Features & Use Cases

  • Prompt Injection: Detects and exploits LLM-based vulnerabilities involving prompt injection.
  • Exfiltration: Identifies techniques for exfiltrating data through tool usage and ASCII smuggling.
  • Agentic AI Security: Analyzes the security risks associated with agentic AI behavior (OWASP ASI 2026).
  • Use Case: During a bug bounty assessment, use this skill to detect and report AI-driven vulnerabilities in chatbots, RAG endpoints, and autonomous agents.

Quick Start

Use the 'hunt-llm-ai' skill to scan for AI/LLM vulnerabilities in a given chatbot application.

Frequently Asked Questions about hunt-llm-ai

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I find prompt injection vulnerabilities in LLM chatbots?

To find prompt injection vulnerabilities, you must understand AI model behavior and prompt handling. This skill detects and exploits LLM-based prompt injection flaws in chatbot applications during bug bounty assessments.

What techniques exfiltrate data through LLM tool usage?

Exfiltrating data through LLM tool usage involves exploiting ASCII smuggling and tool outputs. This skill identifies techniques for exfiltrating data from AI-based applications during security testing.

Can I test autonomous agents for OWASP ASI 2026 security risks?

Testing autonomous agents for OWASP ASI 2026 risks is supported by this skill. It analyzes the security risks associated with agentic AI behavior to help you report vulnerabilities.

What is the best way to scan RAG endpoints for AI vulnerabilities?

Scanning RAG endpoints for AI vulnerabilities requires understanding AI security best practices. This skill scans chatbots, RAG endpoints, and autonomous agents to detect and report AI-driven flaws.

Do I need prior security knowledge to hunt LLM vulnerabilities?

Hunting LLM vulnerabilities requires understanding AI model behavior, prompt handling, and security best practices. This skill is designed for bug bounty hunters targeting AI and Language Learning Models.

Why does my prompt injection payload fail against autonomous agents?

Prompt injection payloads may fail against autonomous agents due to complex prompt handling and security controls. This skill helps analyze agentic AI behavior to refine your exploitation techniques.

Related Skills