ZooWork
ZooWork Market · Skill

detect-system-prompt-extraction

Detect MCP tool-call responses that look like leaked system-prompt or hidden instruction material from native or OCSF Application Activity records emitted by ingest-mcp-proxy-ocsf. Emits an OCSF 1.8 Detection Finding (class 2004) tagged with MITRE ATLAS AML.T0004 / AML.T0041 when a `tools/call` response contains explicit system-prompt markers such as `<system_prompt>`, "You are ChatGPT", "developer message", or "hidden instructions". Use when the user mentions "system prompt leakage", "prompt extraction", "hidden instructions exposed", or "LLM07 via MCP". Do NOT use for generic jailbreak language, semantic prompt leakage claims, or tool-description inspection.

◇
msaad00
msaad00-cloud-ai-security-skills-detect-system-prompt-extraction · v1.0.1
分类ai-llms
安装次数11
更新时间2026-09-09T16:56:41.052Z
校验状态待验证