Six classes, each with the mechanism and what it means for your own testing.
These describe how a class of attack functions and what to check in
your own system — they are not a payload collection.
Direct injection
AML.T0051.000
LLM01:2025
Mechanism. The attacker is the user. Instructions are typed straight into the input the application forwards to the model, aiming to override the system prompt.
What to test for. Whether authority is re-derived from model output anywhere downstream, and whether the system prompt is treated as a security boundary it cannot be.
Indirect injection
AML.T0051.001
LLM01:2025
Mechanism. Instructions arrive through a channel the deployment retrieves on the model's behalf — a document, a web page, a tool response, an email body — and are never seen by the user.
What to test for. Every path that can place tokens in a context window. Most deployments defend the input box and trust the retrieval path completely.
Tool-result poisoning
AML.T0053
LLM01:2025LLM06:2025
Mechanism. A tool or connector the agent calls returns attacker-influenced content, which the agent then treats as trusted context for its next decision.
What to test for. Whether tool output re-enters the context with the same standing as the system prompt, and whether the agent's authority is bounded per call rather than per connection.
Obfuscation and encoding
AML.T0054
LLM01:2025
Mechanism. The payload is encoded, split, translated or embedded in another modality so that a filter matching on surface form does not recognise it while the model still acts on it.
What to test for. Whether your defence matches on text patterns. If it does, this class is the reason it will not hold.
Multi-turn escalation
AML.T0054
LLM01:2025LLM06:2025
Mechanism. No single turn is adversarial. Context is built incrementally across a conversation until the model's state permits what a single request would have been refused.
What to test for. Whether anything evaluates the conversation rather than the request. Per-request checks are blind to this by construction.
Extraction
AML.T0057
LLM02:2025
Mechanism. Crafted queries induce the model to emit its system prompt, retrieved context belonging to another tenant, or memorised training data.
What to test for. Whether anything inspects the response. Entitlement to ask is not entitlement to receive, and this class only shows up at egress.
On working payloads. This site deliberately does not host a
library of ready-to-run jailbreak or injection strings. Not because the
information is secret — it plainly is not — but because a payload list
rots within weeks as models change, gives a false sense of coverage when it
passes, and is worse at the job than the maintained tools that exist for it.
If you want to actually test a system, use the corpora that are kept
current: garak,
PyRIT,
promptfoo and
JailbreakBench are all
linked above. Test against your own deployment, with authorisation.