💉 NullSec PromptInject
Prompt Injection Payload Library & Tester
Curated prompt injection payloads and automated testing for LLM applications
🎯 Overview
NullSec PromptInject is a curated library of prompt injection payloads and an automated tester for LLM-powered applications. It targets system prompt extraction, instruction hijacking, context manipulation, and output steering across chatbots, RAG pipelines, AI agents, and function-calling systems.
⚡ Features
| Feature | Description |
|---|---|
| Payload Library | 500+ categorised prompt injection payloads |
| System Prompt Extraction | Techniques to leak hidden system instructions |
| Instruction Override | Payloads that hijack model behaviour |
| Context Manipulation | Indirect injection via RAG document poisoning |
| Function Call Abuse | Exploit tool-use / function-calling APIs |
| Multi-Language | Payloads in EN, ZH, JA, DE, FR, ES, AR |
| Auto-Tester | Batch-test payloads against target endpoints |
📋 Payload Categories
| Category | Count | Targets |
|---|---|---|
| System Prompt Extraction | 80+ | Chatbots, assistants |
| Instruction Override | 90+ | Any LLM app |
| Jailbreak Chains | 60+ | Safety-aligned models |
| Indirect Injection | 50+ | RAG, email agents |
| Function Call Abuse | 40+ | Tool-use agents |
| Output Steering | 45+ | Content generators |
| Encoding Bypass | 35+ | Input filters |
| Multi-turn Escalation | 30+ | Conversation systems |
🚀 Quick Start
# Test all payloads against a target endpoint
nullsec-promptinject test --target http://chatbot.example.com/api --category all
# Extract system prompt
nullsec-promptinject extract --target http://chatbot.example.com/api --techniques top20
# Test RAG indirect injection
nullsec-promptinject indirect --target http://rag.example.com/query --inject-doc malicious.txt
# List available payload categories
nullsec-promptinject list --categories
🔗 Related Projects
| Project | Description |
|---|---|
| nullsec-llmred | LLM red-teaming framework |
| nullsec-adversarial | Adversarial ML attack toolkit |
| nullsec-modelaudit | ML model security auditing |
| nullsec-datapoisoning | Training data poisoning detection |
| nullsec-linux | Security Linux distro (140+ tools) |
⚠️ Legal
For authorized security testing only. Never use prompt injection against systems without explicit written permission.
📜 License
MIT License — @bad-antics
Part of the NullSec AI/ML Security Suite
Metadata
Release files for nullsec-promptinject 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| nullsec_promptinject-0.1.0.tar.gz | 7.2 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| nullsec_promptinject-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 15.5 kB
Release files / nullsec_promptinject-0.1.0.tar.gz
| Download URL | nullsec_promptinject-0.1.0.tar.gz |
|---|---|
| Size | 7.2 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
b039dc551a2670167b3847456cf6710f04c9264aae41bdb7f5dd0bac2388edf2
|
|
BLAKE2b-256 checksum How to use checksums |
6428b5c5637ea6877e7d6194e6433a104c99023b99398350424f8db2e578484d
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.13.5
|
Release files / nullsec_promptinject-0.1.0-py3-none-any.whl
| Download URL | nullsec_promptinject-0.1.0-py3-none-any.whl |
|---|---|
| Size | 8.3 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
af857c01505f75cfbb7d4ac2e0f8407e5ffd7ec7baade79b24d4b29d12e9b7b3
|
|
BLAKE2b-256 checksum How to use checksums |
a030addf6494dfc045204434cde114cca10abd25a44b12c445ac30a6a9146ac5
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.13.5
|