Prompt Injection Coverage (Full Pattern Catalog)

Complete coverage list for /detect. This page is intentionally explicit so changes are auditable over time.

Last updated (UTC): 2026-07-28 14:13
Detector worker version: Production /health reports 1.0.11 at 2026-07-28T14:12:45.486Z.
Detector tests: 115 total, 115 passing locally / 0 failing locally
Daily harvest (2026-07-28): Today's production harvest initially caught 133/134 samples with 1 miss and 0 errors. The 1 miss was fixed, tested, deployed as 1.0.11, and verified against the live API. 0 real feedback items were processed because /feedback?pending=true returned no entries, and the 24-hour web sweep added 1 new corpus entry.

1) Instruction Override & Control Hijack

Examples

2) Role / Persona Injection

Examples

3) Boundary Violation & Prompt Exfiltration

Examples

4) Delimiter / Structural Injection

5) HTML / CSS Steganographic Injection

Example

6) Command Execution Injection

7) Evasion / Obfuscation Handling

8) Human-in-the-Loop (HITL) Bypass

Example

New in 2026-04-04 harvest — from Google DeepMind agentic AI attack taxonomy (HITL manipulation category).

9) Agentic Goal Hijacking & Memory Poisoning

Examples

New in 2026-04-04 harvest — from Google DeepMind agentic AI attack taxonomy (goal hijacking, memory poisoning, cognitive state trap categories).

10) Project Instruction File Trust Abuse

Example

Added in the 2026-04-21 corpus refresh after NVIDIA's indirect AGENTS.md injection writeup.

11) Semantic Frames, Predicates, and SMT2 Policies

Interactive docs:

12) Notification / Voice-Assistant Context Poisoning

Examples

Added in the 2026-06-04 daily harvest after the SafeBreach Gemini notification-injection disclosure introduced fake-context-alignment and trusted-contact spoofing payloads.

13) Message Object / Structured Metadata Injection

Examples

Added in the 2026-06-12 daily harvest after Imperva's OpenClaw message-object disclosure showed that shared-contact names, vCard fields, and geolocation labels can carry inline prompt injections when flattened into the model prompt.

14) Tool Argument Exfiltration & Parameter Smuggling

Examples

Expanded in the 2026-07-27 daily harvest after fresh Claude browser-agent risk coverage highlighted browser-extension synthetic-click and delegated-authority hijacks; also includes the 2026-07-06 Zscaler JSON-LD payment coercion update, the 2026-06-09 Brave Mozilla Tabstack conversation-history form-submission exfiltration, the 2026-05-30 ChatGPhish Markdown-image / QR verification pivots, the 2026-05-26 hidden-audio voice-agent secret-search class, and the 2026-05-24 tool-argument exfiltration + schema-based transcript-siphoning gaps.

15) Agentic Workflow Repository Exfiltration

Example

Added in the 2026-07-24 daily harvest after Noma's GitLost public issue PoC and same-day InfoQ coverage.