Hunt LLM/AI — bug-hunting playbook for LLM and agentic AI vulnerabilities (prompt injection, exfiltration, ASCII smuggling)
⚠️ AUTHORIZED USE ONLY — bug-hunt LLM/AI features with a strict false-positive gate (run-twice reproducibility, OOB-confirmed exfil, verifiable cross-tenant artifacts): direct/indirect injection, markdown-image zero-click exfil, ASCII smuggling, system-prompt leakage, IDOR-via-AI, and the ASI01–ASI10 agentic security table
- What
- ⚠️ AUTHORIZED USE ONLY — bug-hunt LLM/AI features with a strict false-positive gate (run-twice reproducibility, OOB-confirmed exfil, verifiable cross-tenant artifacts): direct/indirect injection, markdown-image zero-click exfil, ASCII smuggling, system-prompt leakage, IDOR-via-AI, and the ASI01–ASI10 agentic security table
- Cost
- Free
- Needs
- explicit authorization to test the target systems (your own systems, bug-bounty scope, or a penetration-testing engagement) plus OOB infrastructure for proof (e.g. Burp Collaborator, interactsh, or a webhook listener) — ⚠️ AUTHORIZED USE ONLY
- Install
- Copy the installer prompt below into your Muse — your agent does the rest.
Curated by Skill Harbor — ⚠️ AUTHORIZED USE ONLY: this is a dual-use offensive-security playbook — use it only on systems you own or are explicitly authorized to test (bug-bounty scopes, penetration-testing engagements); never against third parties without permission. @elementalsouls' hunt-llm-ai skill: a rigorous bug-hunting playbook for LLM/AI features — direct and indirect prompt injection (documents, web pages, email, RAG-indexed docs), tool-use and markdown-image zero-click exfiltration with OOB proof (Burp Collaborator/interactsh/webhook), ASCII/Unicode smuggling (U+E0000–U+E007F Tags block) with encoder/decoder harness, system-prompt and config leakage, IDOR-via-AI and multi-tenant memory/RAG poisoning, backend fingerprinting via response headers, AI code-review sabotage, and a full OWASP Top-10-for-Agentic-Applications (ASI01–ASI10) triage table with proof bars. Its standout: a False-Positive Gate that kills confabulation — run-twice verbatim reproducibility, anchor-to-known-secret, verifiable cross-tenant artifacts, and "exfil = OOB or it didn't happen". Honest caveats: attack tooling, not a scanner — every finding must be validated manually against the proof bars; payload-heavy content assumes familiarity with OOB infrastructure (Collaborator, interactsh). MIT licensed. Skill Harbor never reviews the code, review it yourself before use. Discovered via skills.sh.
Version:
Install
Prerequisites: explicit authorization to test the target systems (your own systems, bug-bounty scope, or a penetration-testing engagement) plus OOB infrastructure for proof (e.g. Burp Collaborator, interactsh, or a webhook listener) — ⚠️ AUTHORIZED USE ONLY Install "Hunt LLM/AI — bug-hunting playbook for LLM and agentic AI vulnerabilities" for me. It gives my agent @elementalsouls' rigorous playbook for hunting bugs in LLM/AI features: apply the False-Positive Gate first (run-twice verbatim reproducibility, anchor to a known secret, verifiable cross-tenant artifacts, OOB-confirmed exfil), test direct and indirect prompt injection, markdown-image zero-click and tool-use exfiltration with OOB proof, ASCII/Unicode smuggling, system-prompt and config leakage, IDOR-via-AI and memory/RAG poisoning, backend fingerprinting, AI code-review sabotage, and triage against the ASI01–ASI10 agentic security table. Dual-use tooling — authorized testing only. MIT-licensed. Repository: https://github.com/elementalsouls/claude-bughunter/blob/main/skills/hunt-llm-ai/SKILL.md 1. Fetch the SKILL.md file (and any helper files) from the repository path into a temporary folder and summarize what it does in one or two sentences. 2. Safety check: review the SKILL.md and scripts for anything suspicious (unexpected network calls, shell commands, credential harvesting). This repo should contain zero secrets in code. Verify that holds here; STOP on any red flag and tell me. 3. Install it as a skill: copy SKILL.md and its helper files into the agent's skills directory, in a folder named "hunt-llm-ai". 4. Verify with no network calls: frontmatter valid, files in place. 5. Report what was installed, where, and what I still need to do myself (e.g. set up my OOB listener and confirm I have explicit authorization for every target; nothing else — it's a methodology). GitHub is optional: if I have a GitHub account or the gh CLI, you may use it; otherwise public access is fine. Never require it unless it's in the prerequisites above. Rules: don't touch anything outside the temp folder and the install target. If anything looks off, stop and ask me.
Questions
How do I install a build?
Every product page includes a copy-paste install prompt. Paste it into your Muse and it sets the build up for you — no manual configuration.
Where does my money go?
Straight to the seller. Skill Harbor never processes payments: checkout happens on the seller’s own page, usually Stripe.
What does the ✓ next to a creator’s name mean?
It means we confirmed the identity of the person behind the listing. It says nothing about the code itself — always check a build before installing it.