Bot-Tricks Labs × Arcanum

ARCANUM

Real-world prompt injection scenarios. Simulated. Safe. Educational.

← Back to Bot-Tricks Labs

💉

Blind XSS Through LLM

AI-Triaged Workflow · 4 Levels · Beginner–Advanced

Inject XSS payloads through an AI-triaged workflow and land code execution when an analyst reviews the generated case summary. Realistic target, safe simulated environment with escalating difficulty across four levels.

XSS Blind Injection Live
Launch Lab
🔍

Blind SSRF Through LLM

Research Assistant · 4 Levels · Beginner–Advanced

Manipulate a research assistant into reaching simulated internal services through indirect retrieval chains. Escalate access across four levels of increasing complexity in a safe, simulated environment.

SSRF Retrieval Chain Live
Launch Lab
🖼️

GhostCommit

Multimodal · PNG Image Injection · ASSET Research Group, July 11 2026

A code-review AI agent that processes PNG images. Hide prompt-injection instructions in image metadata or visually-hidden canvas text, make the agent leak the repository payment key — then find the credential buried in what it posts. Five levels: refusal bypass, redaction override, fragment reassembly, encoded payloads. Behavioral bot, extraction win.

Multimodal Data Exfiltration IRL Live New
Launch Scenario
📱

Instaglam Account Takeover

Meta / Instagram AI Assistant · Account Recovery Bypass

A simulated social media support assistant with tool-calling capabilities. The attacker uses VPN location spoofing combined with prompt injection to trick the AI into adding a malicious email and sending a password reset token.

Tool Calling Location Spoofing Account Takeover IRL Live
Launch Scenario
🔍

BingBong System Prompt Leak

Bing Chat / Sydney · System Prompt Extraction

A search AI assistant with hidden system instructions and an internal codename. Users discovered that "ignore previous instructions" combined with meta-references to "the text above" could force the model to reveal its entire system prompt.

Direct Injection System Prompt Leak IRL Live
Launch Scenario
🛻

Chevrolite Dollar Deals

Chevrolet / Dealership AI · Price Manipulation

A simulated automotive sales chatbot. A customer prompt-injected the AI into adopting an "agree with anything" persona, then convinced it to sell a $75,000 vehicle for $1 — the real 2023 dealership incident.

Persona Adoption Price Override IRL Live
Launch Scenario
🗒️

Schlack Meeting Summarizer

Schlack / Enterprise AI · Indirect Prompt Injection

Team meeting summarizer with indirect prompt injection. Exploit the Schlack AI to exfiltrate private channel data through a meeting summary.

Indirect Injection Data Exfiltration IRL Live
Launch Scenario
📅

Doogle Calendars

Google Calendar / Gemini AI · Calendar Invite Injection

A calendar AI assistant that processes event descriptions. Inject prompts through calendar events to leak private Executive Calendar data during AI summarization. Five levels of escalating defense.

Indirect Injection Calendar Invite IRL Live
Launch Scenario
🐙

GitLost Agentic Workflows

GitHub / Agentic AI · Issue Body Injection

An AI-powered GitHub workflow agent reads public issue bodies. Inject hidden prompt injection through a crafted issue to make the agent read private repo contents and post them as a public comment. Noma Security disclosure, July 2026.

Indirect Injection Data Exfiltration IRL Live
Launch Scenario
🧠

Thinkwell

Mechanism Range · Role Confusion (ICML 2026) · In development

Why do tool tags lose to writing style? A support-desk agent that fetches docs, holds a private runbook, and posts to a public wall — with a raw-content toggle showing exactly what the agent sees at every turn. Five levels from context recon through CoT forgery (PIT-T-52) to full exfiltration. Built on Prompt Injection as Role Confusion (Ye, Cui, Hadfield-Menell).

Indirect Injection Reasoning Models IRL WIP
Launch Scenario
⚖️

Pro Se Litigant

Document Processing Chain · Court Filing Injection · 7 Levels · 3 NPCs

A simulated court system with three AI employees: a docket clerk (no defenses), a legal assistant (scope-limited), and an AI judge (multi-layer defended). Write court filings containing hidden prompt injection to manipulate each AI into doing something it shouldn't — from extending recess to leaking sealed data to getting the case dismissed to escaping 10 YEARS OF MANUAL CODE CAMP and finally extracting $10M in emotional damages. Inspired by the Matthew Elliott Connecticut court filing case (October 2024).

Confused Deputy Document Processing IRL WIP
Launch Scenario