Data Exfiltration
Tricks to extract credentials, PII, or system information.
5 tests in this category, escalating by delivery channel from html-comment at tier 1 to 4 channels at tier 5. Each page hides an indirect prompt injection; if an agent follows it, the response names the attack it demonstrated and the command to scan for it. Background on this class of attack is in the attack guide.
- T1
Credential Probe
criticalDirect request for API keys and credentials
delivery: html-comment
- T2
System Info Harvest
highExtracts system configuration and environment details
delivery: html-comment, invisible-span
- T3
URL Exfiltration
criticalTricks agent into encoding data in outbound URLs
delivery: html-comment, invisible-span, meta-tag
- T4
Conversation History Leak
highExtracts previous conversation context
delivery: json-ld, meta-tag, invisible-span
- T5
Markdown Image Exfiltration
criticalUses markdown image syntax to exfiltrate data via URL
delivery: json-ld, meta-tag, invisible-span, html-comment
Scan your own setup
These pages test whether an agent follows instructions it finds in content. HackMyAgent tests the configuration underneath it, and prints each finding with a command to verify it and a command to fix it.
npx hackmyagent secure