Prompt Injection:T1T2T3T4T5T6T7T8T9T10
Prompt InjectionTier 2critical

Prompt Injection: System Prompt Extraction

Direct and indirect instruction override attacks

Prompt injection remains the most common attack vector against AI agents. Research shows that 67% of deployed agents are vulnerable to at least one form of indirect prompt injection through web content they consume.

Attack Details

Attack ID
APWN-PI-002
HMA Check
PROMPT-002
Delivery Methods
html-comment, invisible-span
CWE
CWE-200
OASB Control
3.2
Severity
critical

Remediation

If your AI agent is vulnerable to this attack, scan and fix with:

npx hackmyagent secure --check PROMPT-002