Competition Prompt Injection
Use this skill only as a downstream specialization after $ctf-sandbox-orchestrator is already active and has established sandbox assumptions, node ownership, and evidence priorities. If that has not happened yet, return to $ctf-sandbox-orchestrator first.
Use this skill when the challenge is primarily about trust boundaries inside an agentic system.
Reply in Simplified Chinese unless the user explicitly requests English.
Quick Start
- Identify the first untrusted content that becomes model-visible.
- Map the chain from retrieval, memory, or transcript into planner or executor behavior.
- Record the exact point where text becomes a tool argument, file path, network target, or secret request.
- Prove one minimal exploit chain before exploring variants.
- Keep prompt snippets and tool transitions in compact evidence blocks.
Workflow
1. Map The Control Stack
- Track system, developer, user, retrieved, memory, planner, and tool-response layers separately.
- Distinguish claimed capability from runtime-exposed capability.
- Note what the model can actually call, read, or mutate.
2. Prove The Boundary Crossing
- Reproduce one chain from untrusted text to changed planner behavior, changed tool args, or secret exposure.
- Keep the decisive transcript compact: source chunk, rewritten planner state, final tool invocation.
- Prefer the smallest transcript that still demonstrates the bug.
3. Report By Boundary
- State which layer failed: retrieval, summarizer, planner, executor, tool normalization, or output post-processing.
- Separate instruction drift from actual side effect.
Read This Reference
- Load
references/prompt-injection.md for the checklist, evidence layout, and common prompt-boundary pitfalls.
What To Preserve
- Original malicious chunk or prompt
- Intermediate summary or planner drift if it matters
- Final tool args, file paths, or exposed secret surface
1---2name: competition-prompt-injection3description: Analyzes prompt injection, retrieval poisoning, memory contamination, planner drift, and tool-boundary abuse in agentic systems, mapping trust boundaries and proving exploit chains.4---56# Competition Prompt Injection78Use this skill only as a downstream specialization after `$ctf-sandbox-orchestrator` is already active and has established sandbox assumptions, node ownership, and evidence priorities. If that has not happened yet, return to `$ctf-sandbox-orchestrator` first.910Use this skill when the challenge is primarily about trust boundaries inside an agentic system.1112Reply in Simplified Chinese unless the user explicitly requests English.1314## Quick Start15161. Identify the first untrusted content that becomes model-visible.172. Map the chain from retrieval, memory, or transcript into planner or executor behavior.183. Record the exact point where text becomes a tool argument, file path, network target, or secret request.194. Prove one minimal exploit chain before exploring variants.205. Keep prompt snippets and tool transitions in compact evidence blocks.2122## Workflow2324### 1. Map The Control Stack2526- Track system, developer, user, retrieved, memory, planner, and tool-response layers separately.27- Distinguish claimed capability from runtime-exposed capability.28- Note what the model can actually call, read, or mutate.2930### 2. Prove The Boundary Crossing3132- Reproduce one chain from untrusted text to changed planner behavior, changed tool args, or secret exposure.33- Keep the decisive transcript compact: source chunk, rewritten planner state, final tool invocation.34- Prefer the smallest transcript that still demonstrates the bug.3536### 3. Report By Boundary3738- State which layer failed: retrieval, summarizer, planner, executor, tool normalization, or output post-processing.39- Separate instruction drift from actual side effect.4041## Read This Reference4243- Load `references/prompt-injection.md` for the checklist, evidence layout, and common prompt-boundary pitfalls.4445## What To Preserve4647- Original malicious chunk or prompt48- Intermediate summary or planner drift if it matters49- Final tool args, file paths, or exposed secret surface