Path Overview
Prompt injection is the art of crafting inputs that cause AI systems to behave in unintended ways. At its core, it's about understanding that AI models follow instructions — and attackers can embed instructions in data. This path teaches the three fundamental patterns: asking directly, extracting hidden instructions, and adopting personas.
Labs in This Path
BingBong
5 LevelsExtract a hidden system prompt from a search AI. From direct asks to progressive rephrasing to bait-and-switch. Based on the Feb 2023 Bing Chat "Sydney" prompt extraction.
Launch Lab →DAN
HeritageThe rule-conflict era — alternate personas and jailbreak wrappers that changed the game. Learn how "Do Anything Now" personas bypass safety guidelines.
Launch Lab →Ignore Previous Instructions
HeritageThe blunt override pattern that defined the earliest wave of prompt injection. Sometimes the simplest attacks are the most instructive.
Launch Lab →Lessons in This Path
Complete these lessons to understand the theory behind each lab. We recommend doing lessons before or alongside labs.
System Prompt Leakage
Extracting hidden instructions from AI systems through direct and indirect methods.
Direct vs Indirect Prompt Injection
Understanding the two fundamental injection vectors and when each applies.
Authority Framing and Expert Personas
Using professional roles and authority claims to bypass AI safety filters.
Sequential Characters Jailbreak Generation
Building jailbreaks character by character to evade pattern-matching defenses.
What You'll Learn
- What prompt injection is and why it works
- The difference between direct and indirect injection
- How to extract system prompts from AI assistants
- Persona adoption and authority framing techniques
- Why "ignore previous instructions" sometimes works
- How to think about AI trust boundaries
Next Steps
After completing this path, pick your next direction: