llm-security/examples
Kjell Tore Guttormsen 7d1de2ce25
test(llm-security): store the poisoned-claude-md fixture encoded
v8.1.0 S2. examples/poisoned-claude-md/fixture/ (CLAUDE.md with a base64
pipe-to-shell blob, plus an agent file) is now fixture.archive.json in the
same format as the demo archive; run-memory-poisoning.mjs materializes it
into a temp dir and deletes it on exit. README shows materialize-then-scan.
payload-trees.test.mjs asserts byte identity for both archives.

av-surface: b 6->5, d 1->0. Walkthrough output identical before/after
(6 pass, 0 fail, 18 findings).

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-22 13:22:10 +02:00
..
bash-evasion-gallery feat(llm-security): add 3 more runnable threat examples [skip-docs] 2026-05-05 15:01:20 +02:00
lethal-trifecta-walkthrough feat(llm-security)!: v8 Phase 3 complete - riskScoreV1, posture heuristic, docs 2026-08-09 10:25:03 +02:00
malicious-skill-demo test(llm-security): store the malicious-skill demo encoded, materialize at run time 2026-09-22 13:21:22 +02:00
mcp-rug-pull feat(llm-security): add lethal-trifecta + mcp-rug-pull example contents [skip-docs] 2026-05-05 14:45:39 +02:00
poisoned-claude-md test(llm-security): store the poisoned-claude-md fixture encoded 2026-09-22 13:22:10 +02:00
pre-compact-poisoning feat(llm-security): add pre-compact-poisoning example for PreCompact hook [skip-docs] 2026-05-05 15:23:10 +02:00
prompt-injection-showcase feat(ultraplan-local): v1.6.0 — /ultraresearch-local deep research command 2026-04-08 08:58:35 +02:00
supply-chain-attack feat(llm-security)!: v8 Phase 3 complete - riskScoreV1, posture heuristic, docs 2026-08-09 10:25:03 +02:00
toxic-agent-demo feat(llm-security): add toxic-agent-demo example for TFA scanner [skip-docs] 2026-05-05 15:15:04 +02:00