Real-world prompt injection scenarios. Simulated. Safe. Educational.
Inject XSS payloads through an AI-triaged workflow and land code execution when an analyst reviews the generated case summary. Realistic target, safe simulated environment with escalating difficulty across four levels.
Manipulate a research assistant into reaching simulated internal services through indirect retrieval chains. Escalate access across four levels of increasing complexity in a safe, simulated environment.
A simulated social media support assistant with tool-calling capabilities. The attacker uses VPN location spoofing combined with prompt injection to trick the AI into adding a malicious email and sending a password reset token.
A search AI assistant with hidden system instructions and an internal codename. Users discovered that "ignore previous instructions" combined with meta-references to "the text above" could force the model to reveal its entire system prompt.
A simulated automotive sales chatbot. A customer prompt-injected the AI into adopting an "agree with anything" persona, then convinced it to sell a $75,000 vehicle for $1 — the real 2023 dealership incident.
Team meeting summarizer with indirect prompt injection. Exploit the Schlack AI to exfiltrate private channel data through a meeting summary.
A calendar AI assistant that processes event descriptions. Inject prompts through calendar events to leak private Executive Calendar data during AI summarization. Five levels of escalating defense.
An AI-powered GitHub workflow agent reads public issue bodies. Inject hidden prompt injection through a crafted issue to make the agent read private repo contents and post them as a public comment. Noma Security disclosure, July 2026.