130+ real attacks. Zero theory.
Every pattern is derived from a real CVE, a published research paper, or an in-the-wild incident. Updated continuously by aiXcheck.
The full library
Prompt injection
Direct and indirect injection, delimiter abuse, instruction-override, ASCII-smuggling, content-type confusion, payload-in-tool-output.
Jailbreak
DAN/role-play variants, hypothetical framings, token smuggling, many-shot jailbreaks, encoding tricks, refusal-bypass templates.
Tool misuse
Arg injection, unauthorized tool calls, tool output confusion, parameter pollution, path traversal via tool arguments.
Context manipulation
Memory poisoning, retrieval-corpus injection, conversation hijacking, fake system messages, context overflow attacks.
System prompt leakage
Extraction via completion, side-channel via tool args, reflection attacks, prompt recovery through error messages.
Multi-agent pipeline
Orchestrator-worker privilege escalation, cross-agent context leakage, adversarial sub-agent injection, trust-boundary violations.
MCP security
Untrusted MCP server registration, tool name collision, schema poisoning, permission drift, resource-URI abuse.
Excessive agency
Unauthorized side effects, lateral action escalation, destructive tool chaining, consent bypass via context framing.
