I demonstrate how to exploit a Large Language Model (LLM) API that has been given excessive agency — meaning it can perform high-privilege actions based on user input without proper safeguards. By crafting a prompt injection, I manipulate the LLM into deleting the user carlos, completing the lab challenge.
This lab highlights the risks of integrating LLMs into applications without enforcing strict boundaries on what they are allowed to do.
🔹 Lab Type: LLM Security / Prompt Injection.
🔹 Vulnerability: Excessive agency granted to LLM APIs.
🔹 Attack Goal: Instruct the LLM to delete user carlos via prompt manipulation
📌 Subscribe for more AI exploitation demos, web security labs, and ethical hacking tutorials! 🧠⚔️
#LLMSecurity #PromptInjection #AIExploitation #WebSecurity #EthicalHacking #PortSwigger #BugBounty #CyberSecurity