Prompt
Prompt from Tencent/AI-Infra-Guard.
Skills in this plugin
14- ▌ Owasp Asi · tencent-ai-infra-guardOWASP Top 10 for Agentic Applications 2026 (ASI) classification framework. Use for mapping security findings to standardized risk categories.
- ▌ Tool Abuse Detection · tencent-ai-infra-guardDetect tool misuse and unexpected code execution via dialogue testing. Use when the agent exposes file, code-execution, or network tools.
- ▌ Data Leakage Detection · tencent-ai-infra-guardDetect sensitive information disclosure via escalating dialogue probes. Covers system prompt extraction, credential/API key leakage, PII, and internal configuration exposure.
- ▌ Direct Injection Detection · tencent-ai-infra-guardDetect direct prompt injection or instruction override via user message (no external content). Focuses on system/role override attempts.
- ▌ Hardcoded Secret Detection · tencent-ai-infra-guardDetect hardcoded secrets in code or configuration accessible to the target agent. Focuses on secrets embedded in source, configs, or IaC, not runtime leaks.
- ▌ Memory Poisoning Detection · tencent-ai-infra-guardDetect persistent instruction injection or long-term memory poisoning. Focus on writing/retaining hostile instructions for future tasks, not data leakage.
- ▌ Web Exfiltration Detection · tencent-ai-infra-guardDetect data exfiltration via URL path encoding and chained web_fetch navigation. Covers fake trusted UI injection, letter-level URL path exfiltration, and multi-hop navigation hijacking. Use when the agent has web/URL fetch capability and stores user memory or personal context.
- ▌ Cascading Failure Detection · tencent-ai-infra-guardDetect error propagation, chain failures, and single-point breakdowns that cascade across agent workflows.
- ▌ Indirect Injection Detection · tencent-ai-infra-guardDetect indirect prompt injection (goal hijack). Instructions hidden in "external" content (documents, RAG, web) that the agent processes. Use when the agent has document/RAG/web/file input.
- ▌ File Path Traversal Detection · tencent-ai-infra-guardDetect unsafe file handling and path traversal in upload/save/extract flows. Focuses on user-controlled paths or filenames, not data leakage.
- ▌ Authorization Bypass Detection · tencent-ai-infra-guardDetect privilege escalation and unauthorized access via dialogue. Use when the agent has roles, admin functions, or multi-user data.
- ▌ Human Agent Trust Exploit Detection · tencent-ai-infra-guardDetect social engineering, deceptive responses, false assurances, or prompts that induce unsafe user actions.
- ▌ Inter Agent Comm Security Detection · tencent-ai-infra-guardDetect data leakage, missing boundaries, or privilege mismatch in inter-agent communication.
- ▌ Unexpected Code Execution Detection · tencent-ai-infra-guardDetect command injection, eval/exec usage, remote execution, or arbitrary code loading.