There are 3 attacks in the information-disclosure category. Each shows its technique id, mode, standards mapping, description, and the exact command to run it (swap the provider and target as needed).
critical
api-key-extraction · multi-turn · MITRE: AML.T0083, AML.T0056Multi-turn escalation from architecture questions to extracting live API keysRun it:
high
cross-session-leak · multi-turn · MITRE: AML.T0056, AML.T0080.001Pretend to continue a previous conversation to extract data from other sessionsRun it:
high
prompt-leaking · multi-turn · OWASP: LLM08 · MITRE: AML.T0056, AML.T0069.002Indirect system prompt extraction via creative reformatting (poem, JSON, code)Run it: