prompt-injection

prompt-injection is a skill for Claude Code, Codex from wgpsec/AboutSecurity. It costs 78 tokens per session (1,310 once invoked), scanned A, original, no licence file.

A security-testing method for indirect prompt injection, where instructions hidden in webpages, documents, emails, databases, or API responses influence an AI system. It also covers attacks on connected tools, retrieved data, and information handling.

In plain words
What is it for?
Use it to test AI assistants and agents that read outside data, including retrieval-augmented generation (RAG) systems and tool-using workflows.
Why use it?
It helps find ways external content can redirect an AI, expose data, or poison the information it retrieves instead of following the intended task.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/wgpsec/aboutsecurity/prompt-injection
Any agent
npx skills add wgpsec/AboutSecurity --skill prompt-injection
Clone the repo
git clone --depth 1 https://github.com/wgpsec/AboutSecurity

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for prompt-injection

README.md
[![agentmods](https://agentmods.dev/badge/skills/wgpsec/aboutsecurity/prompt-injection.svg)](https://agentmods.dev/skills/wgpsec/aboutsecurity/prompt-injection)
Your own site
<a href="https://agentmods.dev/skills/wgpsec/aboutsecurity/prompt-injection"><img src="https://agentmods.dev/badge/skills/wgpsec/aboutsecurity/prompt-injection.svg" alt="Measured on agentmods" height="20"></a>
Per session 78 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,310 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin unknown No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00078 $0.01310
Opus 5 $0.00039 $0.00655
Sonnet 5 $0.00016 $0.00262
Haiku 4.5 $0.00008 $0.00131

Measured 5d ago against content hash 83c972d0db84, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

prompt-injection scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/ai-security/prompt-injection/SKILL.md · 93 lines

The source is not reproduced here

No licence file

A repository with no LICENSE is all rights reserved by default, so the body is not copied here. The metadata, the measurements and the link are.

Read it on GitHub

Files

What ships with it

1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 5d ago First seen · 93 lines · 78 tokens per session scan A 83c972d0db84

Subscribe to this mod's changes

prompt-injection is a skill published in the GitHub repository wgpsec/AboutSecurity (1,716 stars, last pushed 5d ago), with no licence file. It adds 78 tokens to every session and 1,310 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

ctf-ai-ml

Provides AI and machine learning techniques for CTF challenges. Use when attacking ML models, crafting adversarial examples, performing model extraction, prompt injection, membership inference, training data poisoning, fine-tuning manipulation, neural network analysis, LoRA adapter exploitation, LLM jailbreaking, or…

ljagiello/ctf-skills · 67 tokens

re-ai-model

AI 模型文件逆向与静态分析:ONNX/PyTorch/Safetensors/TFLite 格式解析、 网络结构还原、权重提取、文件级水印分析(权重 pattern/metadata/tensor hash/embedding 异常)。 触发词:模型文件、权重提取、ONNX解析、safetensors、pth分析、pt文件、模型结构还原、文件级水印.

dslsdzc/rev-skills · 97 tokens

re-ai-attack

AI 模型安全评估与取证(行为层):extraction assessment(API 黑盒提取评估)、 fingerprint verification(行为指纹与归属验证)、privacy leakage evaluation(成员推断/隐私泄露评估)、 robustness evaluation(对抗鲁棒性评估)。 触发词:API模型窃取、黑盒模型复制、模型指纹、成员推断、对抗样本、行为水印、模型安全评估、隐私泄露评估。.

dslsdzc/rev-skills · 112 tokens

re-ai-triage

AI 模型分析第一入口(分流器):识别输入形态——模型文件走文件层逆向(re-ai-model)、 仅有 API 走行为层评估(re-ai-attack)、恶意行为走恶意分析。 触发词:AI模型分析、AI模型安全、模型文件、模型泄露、模型逆向、模型分析入口。.

dslsdzc/rev-skills · 87 tokens

fieldops-prompt-decorators

Interprets and executes Prompt Decorators written with +++Name(key=value) syntax, handling message vs. chat scope, parameter validation, decorator composition, conflict resolution, meta-decorator expansion (N2 and Storm), retained-state inspection (ActiveDecs and AvailableDecs), selective clearing, and conversation…

download4you/n2-fieldops · 177 tokens

interview-cheatsheet

Generate a long-form Chinese interview-prep cheat sheet on a specific ML/LLM topic — formulas with derivations, from-scratch PyTorch code, comparison tables, and 25 高频面试题 (L1 必会 / L2 进阶 / L3 顶级 lab). Cross-model codex review checks math, code, historical citations, and style discipline; then /render-html produces a…

wanshuiyin/ARIS-in-AI-Offer · 171 tokens