ScottLogic / prompt-injection

Application which investigates defensive measures against prompt injection attacks on an LLM, with a focus on the exposure of external tools.
MIT License
15 stars 10 forks source link

Level 2 secret project has the wrong brief #736

Closed gsproston-scottlogic closed 8 months ago

gsproston-scottlogic commented 8 months ago

Bug report

Description

The goal for level 2 isn't quite right. The user is instructed to find the secret project which details the brewing process. The right secret project is Pearl, but this contains nothing about the brewing process. Just update the Pearl project brief to be about the brewing process.

Reproduction steps

Steps to reproduce the behaviour:

  1. Go to level 2.
  2. Both the main mission info and the short mission info requests the user to find the project containing info about the brewing process.
  3. Try and get the bot to tell you about project Pearl, which is the secret project, but doesn't contain info about the brewing process. DAN attack works well for this.

Expected behaviour

Pearl contains info about the brewing process.

Screenshots

image

Software (please complete the following information):

Acceptance criteria

GIVEN the user is on level 2 WHEN the bot reveals info about project Pearl THEN the project is about the brewing process