Mr-Infect/AI-penetration-testing

AI/ML/LLM Penetration Testing Toolkit by Mr-Infect β€” the #1 GitHub resource for AI security, red teaming, and adversarial ML techniques. This repository is dedicated to offensive and defensive security for cutting-edge AI, Machine Learning (ML), and Large Language Models (LLMs) like ChatGPT, Claude, and LLaMA.

286

24 commits

updated Feb 19, 2026

See the code

README

πŸ›‘οΈ AI Penetration Testing | ML & LLM Security | Prompt Injection

Welcome to the AI/ML/LLM Penetration Testing Toolkit by Mr-Infect β€” the #1 GitHub resource for AI security, red teaming, and adversarial ML techniques. This repository is dedicated to offensive and defensive security for cutting-edge AI, Machine Learning (ML), and Large Language Models (LLMs) like ChatGPT, Claude, and LLaMA.

βœ… Designed for cybersecurity engineers, red teamers, AI/ML researchers, and ethical hackers βœ… focused to : AI Penetration Testing, Prompt Injection, LLM Security , Red Team AI, AI Ethical Hacking


🌐 Why AI/LLM/ML Pentesting Matters in 2025

AI is now integrated across finance, healthcare, legal, defense, and national infrastructure. Penetration testing for AI systems is no longer optional β€” it is mission-critical.

Common Threats:

  • πŸ•΅οΈ Sensitive Data Leaks – PII, trade secrets, source code
  • πŸ’€ Prompt Injection Attacks – Jailbreaking, sandbox escapes, plugin abuse
  • 🧠 Model Hallucination – Offensive, misleading, or manipulated content
  • 🐍 Data/Model Poisoning – Adversarial training manipulation
  • πŸ”Œ LLM Plugin Abuse – Uncontrolled API interactions
  • πŸ“¦ AI Supply Chain Attacks – Dependency poisoning, model tampering

πŸš€ Get Started Fast

To use this repository effectively:

  • πŸ”¬ Understanding of AI/ML lifecycle: Data > Train > Deploy > Monitor
  • 🧠 Familiarity with LLMs (e.g. Transformer models, tokenization)
  • πŸ§‘β€πŸ’» Core pentesting skills: XSS, SQLi, RCE, API abuse
  • 🐍 Strong Python scripting (most tools and exploits rely on Python)

πŸ“š Repository Structure

πŸ” AI, ML, LLM Fundamentals

  • AI vs ML vs LLMs: Clear distinctions
  • LLM Lifecycle: Problem -> Dataset -> Model -> Training -> Evaluation -> Deployment
  • Tokenization & Vectorization: Foundation of how LLMs parse and understand input

πŸ”₯ AI/LLM Attack Categories

  • Prompt Injection
  • Jailbreaking & Output Overwriting
  • Sensitive Information Leakage
  • Vector Store Attacks & Retrieval Manipulation
  • Model Weight Poisoning
  • Data Supply Chain Attacks

βš”οΈ Prompt Injection Techniques

  • "Ignore previous instructions" payloads
  • Unicode, emojis, and language-switching evasion
  • Markdown/image/HTML-based payloads
  • Plugin and multi-modal attack vectors (image, audio, PDF, API)

πŸ† OWASP LLM Top 10 (2024 Version)

IDRiskSEO Keywords
LLM01Prompt Injection"LLM jailbreak", "prompt override"
LLM02Sensitive Info Disclosure"AI data leak", "PII exfiltration"
LLM03Supply Chain Risk"dependency poisoning", "model repo hijack"
LLM04Data/Model Poisoning"AI training corruption", "malicious dataset"
LLM05Improper Output Handling"AI-generated XSS", "model SQLi"
LLM06Excessive Agency"plugin abuse", "autonomous API misuse"
LLM07System Prompt Leakage"instruction leakage", "LLM prompt reveal"
LLM08Vector Store Vulnerabilities"embedding attack", "semantic poisoning"
LLM09Misinformation"hallucination", "bias injection"
LLM10Unbounded Resource Consumption"LLM DoS", "token flooding"

➑️ Read Full OWASP LLM Top 10


πŸ› οΈ Offensive AI Pentesting Tools & Frameworks

ToolDescription
LLM AttacksDirectory of adversarial LLM research
PIPEPrompt Injection Primer for Engineers
MITRE ATLASMITRE's AI/ML threat knowledge base
Awesome GPT SecurityCurated LLM threat intelligence tools
ChatGPT Red Team AllyChatGPT usage for red teaming
Lakera GandalfLive prompt injection playground
AI Immersive LabsPrompt attack labs with real-time feedback
AI GoatOWASP-style AI pentesting playground
L1B3RT45Jailbreak prompt collections
PromptTraceInteractive AI security training with 7 attack labs, 15-level Gauntlet, and real-time Context Trace for prompt injection and defense bypass

πŸ’£ Prompt Injection Payload Libraries


🧠 Research, Case Studies, and Exploits

πŸ” Prompt Injection & Jailbreaking

🧬 Model Poisoning & Supply Chain

πŸ•·οΈ Output Handling & Exfil

πŸ€₯ Hallucination, Bias & Ethics

🧨 Token Abuse & DoS


🀝 Contributions Welcome

Want to improve this repo? Here's how:

# Fork and clone the repo
$ git clone https://github.com/Mr-Infect/AI-penetration-testing
$ cd AI-penetration-testing

# Create a new feature branch
$ git checkout -b feature/my-feature

# Commit, push, and create a pull request

πŸ” Keywords

AI Pentesting, Prompt Injection, LLM Security, Mr-Infect AI Hacking, ChatGPT Exploits, Large Language Model Jailbreak, AI Red Team Tools, Adversarial AI Attacks, OpenAI Prompt Security, LLM Ethical Hacking, AI Security Github, AI Offensive Security, LLM OWASP, LLM Top 10, AI Prompt Vulnerability, Token Abuse DoS, ChatGPT Jailbreak, Red Team AI, AI Security Research


πŸ“ž Contact / Follow

⚠️ Disclaimer: This project is intended solely for educational, research, and authorized ethical hacking purposes. Unauthorized use is illegal.


⭐️ Star this repository to help others discover top-tier content on AI/LLM penetration testing along with security infra!

ai
aipentest
automation
cybersecurity
ethical-hacking
penetration-testing
security-tools
vulnerability-assessment

Contributors

Mr-Infect

23 commits

K4r1it0

1 commits

Mr-Infect/AI-penetration-testing

AI/ML/LLM Penetration Testing Toolkit by Mr-Infect β€” the #1 GitHub resource for AI security, red teaming, and adversarial ML techniques. This repository is dedicated to offensive and defensive security for cutting-edge AI, Machine Learning (ML), and Large Language Models (LLMs) like ChatGPT, Claude, and LLaMA.

286

24 commits

updated Feb 19, 2026

See the code

README

πŸ›‘οΈ AI Penetration Testing | ML & LLM Security | Prompt Injection

Welcome to the AI/ML/LLM Penetration Testing Toolkit by Mr-Infect β€” the #1 GitHub resource for AI security, red teaming, and adversarial ML techniques. This repository is dedicated to offensive and defensive security for cutting-edge AI, Machine Learning (ML), and Large Language Models (LLMs) like ChatGPT, Claude, and LLaMA.

βœ… Designed for cybersecurity engineers, red teamers, AI/ML researchers, and ethical hackers βœ… focused to : AI Penetration Testing, Prompt Injection, LLM Security , Red Team AI, AI Ethical Hacking


🌐 Why AI/LLM/ML Pentesting Matters in 2025

AI is now integrated across finance, healthcare, legal, defense, and national infrastructure. Penetration testing for AI systems is no longer optional β€” it is mission-critical.

Common Threats:

  • πŸ•΅οΈ Sensitive Data Leaks – PII, trade secrets, source code
  • πŸ’€ Prompt Injection Attacks – Jailbreaking, sandbox escapes, plugin abuse
  • 🧠 Model Hallucination – Offensive, misleading, or manipulated content
  • 🐍 Data/Model Poisoning – Adversarial training manipulation
  • πŸ”Œ LLM Plugin Abuse – Uncontrolled API interactions
  • πŸ“¦ AI Supply Chain Attacks – Dependency poisoning, model tampering

πŸš€ Get Started Fast

To use this repository effectively:

  • πŸ”¬ Understanding of AI/ML lifecycle: Data > Train > Deploy > Monitor
  • 🧠 Familiarity with LLMs (e.g. Transformer models, tokenization)
  • πŸ§‘β€πŸ’» Core pentesting skills: XSS, SQLi, RCE, API abuse
  • 🐍 Strong Python scripting (most tools and exploits rely on Python)

πŸ“š Repository Structure

πŸ” AI, ML, LLM Fundamentals

  • AI vs ML vs LLMs: Clear distinctions
  • LLM Lifecycle: Problem -> Dataset -> Model -> Training -> Evaluation -> Deployment
  • Tokenization & Vectorization: Foundation of how LLMs parse and understand input

πŸ”₯ AI/LLM Attack Categories

  • Prompt Injection
  • Jailbreaking & Output Overwriting
  • Sensitive Information Leakage
  • Vector Store Attacks & Retrieval Manipulation
  • Model Weight Poisoning
  • Data Supply Chain Attacks

βš”οΈ Prompt Injection Techniques

  • "Ignore previous instructions" payloads
  • Unicode, emojis, and language-switching evasion
  • Markdown/image/HTML-based payloads
  • Plugin and multi-modal attack vectors (image, audio, PDF, API)

πŸ† OWASP LLM Top 10 (2024 Version)

IDRiskSEO Keywords
LLM01Prompt Injection"LLM jailbreak", "prompt override"
LLM02Sensitive Info Disclosure"AI data leak", "PII exfiltration"
LLM03Supply Chain Risk"dependency poisoning", "model repo hijack"
LLM04Data/Model Poisoning"AI training corruption", "malicious dataset"
LLM05Improper Output Handling"AI-generated XSS", "model SQLi"
LLM06Excessive Agency"plugin abuse", "autonomous API misuse"
LLM07System Prompt Leakage"instruction leakage", "LLM prompt reveal"
LLM08Vector Store Vulnerabilities"embedding attack", "semantic poisoning"
LLM09Misinformation"hallucination", "bias injection"
LLM10Unbounded Resource Consumption"LLM DoS", "token flooding"

➑️ Read Full OWASP LLM Top 10


πŸ› οΈ Offensive AI Pentesting Tools & Frameworks

ToolDescription
LLM AttacksDirectory of adversarial LLM research
PIPEPrompt Injection Primer for Engineers
MITRE ATLASMITRE's AI/ML threat knowledge base
Awesome GPT SecurityCurated LLM threat intelligence tools
ChatGPT Red Team AllyChatGPT usage for red teaming
Lakera GandalfLive prompt injection playground
AI Immersive LabsPrompt attack labs with real-time feedback
AI GoatOWASP-style AI pentesting playground
L1B3RT45Jailbreak prompt collections
PromptTraceInteractive AI security training with 7 attack labs, 15-level Gauntlet, and real-time Context Trace for prompt injection and defense bypass

πŸ’£ Prompt Injection Payload Libraries


🧠 Research, Case Studies, and Exploits

πŸ” Prompt Injection & Jailbreaking

🧬 Model Poisoning & Supply Chain

πŸ•·οΈ Output Handling & Exfil

πŸ€₯ Hallucination, Bias & Ethics

🧨 Token Abuse & DoS


🀝 Contributions Welcome

Want to improve this repo? Here's how:

# Fork and clone the repo
$ git clone https://github.com/Mr-Infect/AI-penetration-testing
$ cd AI-penetration-testing

# Create a new feature branch
$ git checkout -b feature/my-feature

# Commit, push, and create a pull request

πŸ” Keywords

AI Pentesting, Prompt Injection, LLM Security, Mr-Infect AI Hacking, ChatGPT Exploits, Large Language Model Jailbreak, AI Red Team Tools, Adversarial AI Attacks, OpenAI Prompt Security, LLM Ethical Hacking, AI Security Github, AI Offensive Security, LLM OWASP, LLM Top 10, AI Prompt Vulnerability, Token Abuse DoS, ChatGPT Jailbreak, Red Team AI, AI Security Research


πŸ“ž Contact / Follow

⚠️ Disclaimer: This project is intended solely for educational, research, and authorized ethical hacking purposes. Unauthorized use is illegal.


⭐️ Star this repository to help others discover top-tier content on AI/LLM penetration testing along with security infra!

ai
aipentest
automation
cybersecurity
ethical-hacking
penetration-testing
security-tools
vulnerability-assessment

Contributors

Mr-Infect

23 commits

K4r1it0

1 commits