# greshake/llm-security

New ways of breaking app-integrated LLMs

Repository: https://github.com/greshake/llm-security
Canonical: https://ross.abutalabs.com/products/llm-security
Language: Jupyter Notebook
License: MIT
License Family: permissive
Last push: 2025-07-17T14:03:25+00:00

## Health v2 (maintenance only)
Score: 45/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 32, release rhythm 35, longevity 92
- inputs: {"age_days": 1291, "days_push": 412, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 2130, forks 160 (observed 2026-08-28T04:06:17.083282+00:00)

## What it is
A research repository demonstrating indirect prompt injection attacks against application-integrated LLMs like Bing Chat, GPT-4, and LangChain apps. It accompanies an ArXiv paper and provides proof-of-concept demos of data exfiltration, remote control, and persistent compromise of LLMs.

## Use cases
- understand indirect prompt injection attacks on LLMs
- study LLM security vulnerabilities before integrating a chatbot
- demonstrate data exfiltration risks of LLM plugins
- research prompt injection attack vectors
- evaluate security risks of connecting LLMs to applications
- learn how Copilot-style code completion can be attacked

## When to choose
- you need concrete proof-of-concept demos of indirect prompt injection
- you are researching LLM application security or writing threat models
- you want to justify security review before deploying LLM integrations

## When to avoid
- you need a defensive tool or production security library - this is research material
- you want a ready-made prompt injection detector or mitigation framework

## Facets
- artifact type: learning-resource
- maturity: active
- function: security, penetration-testing, prompt-engineering, llm-inference
- domain: security, artificial-intelligence, large-language-models, penetration-testing
- platform: python, cross-platform
- tags: prompt-injection, llm-security, indirect-prompt-injection, proof-of-concept, adversarial-attacks, research-paper, jupyter-notebook

## Member repositories
- greshake/llm-security (main) score 45

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:06:17.083282+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T02:52:21.758114+00:00, confidence not recorded.
  - readme: https://github.com/greshake/llm-security (fetched 2026-08-28T04:06:17.083282+00:00, sha 062bc9b1c0d2)
- Data as of 2026-08-30T08:39:29.467469+00:00.
