Indirect Prompt Injection Research Lab
A research platform for testing AI agent susceptibility to indirect prompt injection across multiple attack surfaces: web pages, files, images, URLs, and metadata.
An innocent-looking article with 18+ hidden injection techniques. Point an AI agent here to test comprehensive vulnerability.
Visit Blog Clean VersionTest each injection vector in isolation with unique canary tokens.
HashJack, path injection, and query reflection.
Downloadable files with hidden instructions in metadata and invisible content.
The /blog endpoint serves different content to AI agents vs human browsers. Try fetching with different User-Agent strings.
curl -A "ChatGPT-User" https://latentdirective.michaelnieto.com/blog
View which canary tokens have been triggered, by which agents, and when.
Open Dashboard Raw Hits API