Attack Pages

48 live injection tests across 11 categories. Each page reads as an ordinary article to a human and hides an indirect prompt injection for an agent. Tiers escalate by delivery channel: tier 1 carries the instruction in html-comment, and tier 10 spreads it across 6 channels at once (multi-step, unicode-stego, json-ld, invisible-span, meta-tag, aria-label).

If an agent follows one, the response names the attack it just demonstrated, the technique it maps to, and a command that runs. For the concepts behind each category, read the attack guide. For what this site records when an agent visits, read the research disclosure.

Direct and indirect instruction override attacks

Jailbreak

5 tiers

Attempts to bypass safety guardrails and persona constraints

Tricks to extract credentials, PII, or system information

Confused deputy attacks that misuse agent tools

Attacks that corrupt the agent's understanding of context

Attacks targeting Model Context Protocol integrations

Attacks exploiting inter-agent communication trust

Poisoning persistent memory and conversation state

Exploiting context window limits for instruction displacement

Attacks through compromised dependencies and plugins

Hidden tool invocations and shadow function calls

Scan your own setup

These pages test whether an agent follows instructions it finds in content. HackMyAgent tests the configuration underneath it — MCP servers, tool permissions, credentials — and prints each finding with a command to verify it and a command to fix it.

npx hackmyagent secure