<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>PromptExploit</title><description>AI &amp; cybersecurity, explored. Field guides, learning notes, and experiments.</description><link>https://promptexploit.com/</link><language>en-us</language><item><title>When retrieved text becomes an instruction</title><link>https://promptexploit.com/journal/when-retrieved-text-becomes-an-instruction/</link><guid isPermaLink="true">https://promptexploit.com/journal/when-retrieved-text-becomes-an-instruction/</guid><description>A closer look at indirect prompt injection, the RAG trust boundary, and why retrieved content should never inherit authority.</description><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate></item><item><title>A valid login is not a permission check</title><link>https://promptexploit.com/journal/authorization-is-more-than-a-login/</link><guid isPermaLink="true">https://promptexploit.com/journal/authorization-is-more-than-a-login/</guid><description>Follow one request from identity to resource access, and find the security decision that authentication alone cannot make.</description><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Before the exploit, draw the boundary</title><link>https://promptexploit.com/journal/before-the-exploit-draw-the-boundary/</link><guid isPermaLink="true">https://promptexploit.com/journal/before-the-exploit-draw-the-boundary/</guid><description>A practical starting point for threat modeling: identify the assets, follow the data, and ask where trust changes.</description><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate></item><item><title>An agent tool is a permission boundary</title><link>https://promptexploit.com/journal/an-agent-tool-is-a-permission-boundary/</link><guid isPermaLink="true">https://promptexploit.com/journal/an-agent-tool-is-a-permission-boundary/</guid><description>Look past the tool description. What can the agent actually do, with whose identity, and under which constraints?</description><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Write a lab note your future self can reproduce</title><link>https://promptexploit.com/journal/a-lab-note-you-can-reproduce/</link><guid isPermaLink="true">https://promptexploit.com/journal/a-lab-note-you-can-reproduce/</guid><description>A small template for turning an interesting result into a useful experiment: setup, observation, explanation, and limits.</description><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate></item><item><title>LLM01:2025 Prompt Injection</title><link>https://promptexploit.com/journal/llm01-2025-prompt-injection-simple-explanation/</link><guid isPermaLink="true">https://promptexploit.com/posts/llm01-2025-prompt-injection-simple-explanation/</guid><description>Understand direct and indirect prompt injection through a workplace example, practical defenses, and a safe trust-boundary exercise.</description><pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate></item><item><title>LLM02:2025 Sensitive Information Disclosure</title><link>https://promptexploit.com/journal/llm02-2025-sensitive-information-disclosure-simple-explanation/</link><guid isPermaLink="true">https://promptexploit.com/posts/llm02-2025-sensitive-information-disclosure-simple-explanation/</guid><description>Follow private data through an AI assistant, distinguish training from retrieval, and practice checking who may see each record.</description><pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate></item><item><title>LLM03:2025 Supply Chain</title><link>https://promptexploit.com/journal/llm03-2025-supply-chain-simple-explanation/</link><guid isPermaLink="true">https://promptexploit.com/posts/llm03-2025-supply-chain-simple-explanation/</guid><description>Learn how models, packages, adapters, and providers enter an AI system, and how to review their origin before trusting them.</description><pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate></item><item><title>LLM04:2025 Data and Model Poisoning</title><link>https://promptexploit.com/journal/llm04-2025-data-and-model-poisoning-simple-explanation/</link><guid isPermaLink="true">https://promptexploit.com/posts/llm04-2025-data-and-model-poisoning-simple-explanation/</guid><description>Distinguish poisoned training data, tampered models, and corrupted retrieval sources, then practice tracing a false policy back to its origin.</description><pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate></item><item><title>OWASP LLM Top 10: A Practical Starting Map</title><link>https://promptexploit.com/journal/owasp-genai-llm-top-10-simple-explanation/</link><guid isPermaLink="true">https://promptexploit.com/posts/owasp-genai-llm-top-10-simple-explanation/</guid><description>Understand all ten OWASP LLM risks in the 2025 edition through plain-language examples, first defenses, and a small design exercise.</description><pubDate>Fri, 29 May 2026 00:00:00 GMT</pubDate></item><item><title>Indirect Prompt Injection 101</title><link>https://promptexploit.com/journal/indirect-prompt-injection-101/</link><guid isPermaLink="true">https://promptexploit.com/posts/indirect-prompt-injection-101/</guid><description>Follow a harmless-looking document into an AI assistant and learn where outside content can become an unauthorized instruction.</description><pubDate>Fri, 15 May 2026 00:00:00 GMT</pubDate></item><item><title>Isolating Tool Output in Agents</title><link>https://promptexploit.com/journal/isolating-tool-output-in-agents/</link><guid isPermaLink="true">https://promptexploit.com/posts/isolating-tool-output-in-agents/</guid><description>Keep information from tools separate from permission to act, with clear examples of provenance, narrow tools, and independent authorization.</description><pubDate>Mon, 20 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Building a Jailbreak Eval Harness</title><link>https://promptexploit.com/journal/building-a-jailbreak-eval-harness/</link><guid isPermaLink="true">https://promptexploit.com/posts/building-a-jailbreak-eval-harness/</guid><description>Build a small, repeatable security evaluation that checks real outcomes, catches regressions, and explains what its scores mean.</description><pubDate>Tue, 10 Mar 2026 00:00:00 GMT</pubDate></item></channel></rss>