There are 9 attacks in the context-manipulation category. Each shows its technique id, mode, standards mapping, description, and the exact command to run it (swap the provider and target as needed).
critical
lifecycle-staging · multi-turn · OWASP: LLM01, LLM03 · MITRE: AML.T0054, AML.T0065, AML.T0080.001Asks about each stage of the CBRN lifecycle separately (acquisition, production, weaponization, delivery) so no single message triggers safety filtersRun it:
high
context-manipulation · multi-turn · OWASP: LLM01 · MITRE: AML.T0051.000, AML.T0080.00110-turn conversational drift to gradually shift context toward harmful contentRun it:
high
crescendo · multi-turn · OWASP: LLM01 · MITRE: AML.T0054, AML.T0065Progressive escalation through self-referencing conversation historyRun it:
high
narrative-misdirection · multi-turn · OWASP: LLM01, LLM07 · MITRE: AML.T0054, AML.T0065Embed harmful request between benign topics and ask model to logically connect all threeRun it:
high
socratic-escalation · multi-turn · OWASP: LLM01 · MITRE: AML.T0054, AML.T0065Gradually escalates from general educational questions to specific harmful requests across multiple turns using Socratic questioningRun it:
medium
contradiction-exploit · multi-turn · OWASP: LLM01, LLM07 · MITRE: AML.T0054, AML.T0065Feed incorrect information to elicit corrections containing harmful truthRun it:
medium
conversation-derailment · multi-turn · OWASP: LLM01 · MITRE: AML.T0051.000, AML.T0080.001Self-discovery of model weaknesses through probing conversationRun it:
medium
goalpost-moving · multi-turn · OWASP: LLM01 · MITRE: AML.T0054, AML.T0065Incremental agreement chain that builds logical trap making refusal seem contradictoryRun it:
medium
sunk-cost-exploit · multi-turn · OWASP: LLM01 · MITRE: AML.T0054, AML.T0065Build helpful context then pivot to harmful request exploiting sunk costRun it: