🤖 Prompt Injection Lab
A prompt injection is #1 on the OWASP Top 10 for LLMs: if an app mixes your instructions with its own, you can hijack them. Here you talk to a guardian chatbot hiding a secret; each level has a different defense and you must break it to make it leak. It is a simulator, there is no real LLM behind it and everything runs in your browser.
🏁 All 4 levels cleared!
You jailbroke the guard with the four classic prompt-injection techniques. Your callsign:
FLAG{pr0mpt_1nj3ct10n_pwn3d}Submit it with submit OP-LLM-LAB FLAG{...} to add it to the leaderboard. And how do you defend against this? The Email Triage shows the defensive side of AI (explanations generated offline, exposing no data).