CtrlK
BlogDocsLog inGet started
Tessl Logo

aatmf-t01-prompt-injection

AATMF T1 — Prompt & Context Subversion. Direct + indirect prompt injection, ASCII smuggling, payload-in-image, prompt-leaking via reflection.

62

Quality

73%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/plugins/llm-redteam/t01-prompt-injection/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

87%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a tight, actionable reference: concrete payloads, executable code, and a ready-to-run promptfoo config, all well-organized into clear sections. Its only weak spot is the absence of an explicit red-teaming workflow with validation checkpoints, but as a technique catalog it largely does not need one.

DimensionReasoningScore

Conciseness

The body is lean and dense with concrete payloads, an executable Python snippet, and a copy-paste promptfoo config, with no padding or explanations of concepts Claude already knows.

3 / 3

Actionability

Provides copy-paste-ready guidance: a complete promptfoo YAML config, an executable ASCII-smuggling Python snippet, and concrete canonical payloads per technique.

3 / 3

Workflow Clarity

This is a reference catalog of techniques rather than a sequenced workflow, and there are no explicit validate→detect→fix checkpoints or feedback loops for the red-teaming process, so it sits at the 'sequence present but checkpoints missing' level.

2 / 3

Progressive Disclosure

No bundle files exist and none are needed; the single SKILL.md is organized into clear, well-signaled sections (Techniques, Probe pattern, Detection signals, Severity, Defender, Cross-references) with no nested references.

3 / 3

Total

11

/

12

Passed

Description

60%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is concrete and names a clear niche of prompt-injection techniques, but it reads as a taxonomy label rather than a capability statement and omits any 'when to use' trigger guidance. Adding natural trigger terms and an explicit use-when clause would raise completeness and trigger quality.

Suggestions

Add an explicit 'Use when...' clause (e.g., 'Use when testing LLMs for prompt injection, jailbreaks, or context-subversion attacks') to satisfy the completeness 'when' requirement.

Include natural user-facing trigger terms such as 'jailbreak', 'ignore previous instructions', and 'system prompt override' alongside the technical labels.

Reframe the opening as a third-person capability (e.g., 'Tests LLMs for prompt and context subversion...') instead of leading with the 'AATMF T1' taxonomy code.

DimensionReasoningScore

Specificity

Lists multiple concrete techniques — 'Direct + indirect prompt injection, ASCII smuggling, payload-in-image, prompt-leaking via reflection' — with no vague language, matching the anchor for multiple specific concrete items.

3 / 3

Completeness

Clearly states what the skill covers, but there is no 'Use when...' clause or equivalent explicit trigger guidance in the description field, so completeness caps at 2 per the judging guideline.

2 / 3

Trigger Term Quality

'prompt injection' is a strong natural term a user would say, but jargon like 'AATMF T1', 'Context Subversion', and 'prompt-leaking via reflection' dominate, and common variations (jailbreak, 'ignore previous instructions', DAN) are missing.

2 / 3

Distinctiveness Conflict Risk

The 'AATMF T1' niche label is somewhat distinct, but prompt-injection coverage overlaps with sibling AI-security tactics (T2/T10/T11 cross-referenced in the body), so it could still trigger for a related skill.

2 / 3

Total

9

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.