docs: SEC-I01 LLM attacker prompt pack [SEC-I01] #446
Labels
No labels
agent:fix_bugfix
agent:fix_conflicts
agent:fix_security
agent:gap_analysis
agent:implement
agent:implement
agent:implement
agent:open_issues
agent:ready
agent:research
agent:security_audit
agent:verify
architecture
backend
blocker:hybrid
blocker:launch
blocker:limit-orders
blocker:v2
block:log_only
block:security
bug
ci
contracts
correctness
deploy
dev
devops
docs
documentation
duplicate
e2e
enhancement
epic
feature
frontend
functional-completion
gas
good first issue
governance
help wanted
high-risk
hooks
hybrid
indexer
infra
infrastructure
integrators
invalid
launch-blocker
limit-orders
localnet
localterra
low priority
missing-implementation
needs-design
ops
performance
priority
high
priority
medium
product
qa
QA
question
ready
ready
research
scripts
security
security-hardening
smartcontracts
tech-debt
testing
ux
UX
v2
verification
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
code/cl8y-dex-terraclassic#446
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
LLM attacker prompt pack created and saved at
help/sec-i-prompt-pack.md. The pack models all 10 historical exploit themes from the checklist preamble against this repo's specific code, generates exploit hypotheses, and triages each result.What Was Done
Built 17 exploit hypotheses (H01-H17) derived from all 10 historical exploit themes in the checklist preamble, plus two novel hypotheses from direct codebase review (H16, H17). Each hypothesis includes a verbatim adversarial prompt parameterized with actual file paths and line numbers, the generated exploit scenario, and a triage verdict.
Full prompt pack artifact:
help/sec-i-prompt-pack.mdCovered (6)
Not Applicable (2)
Risk Accepted (4)
Real Gap (4, feed into SEC-I02)
Partially Covered (1)
Artifact
help/sec-i-prompt-pack.mdVerification Checklist
Labels
security,pre-launch~"block:log_only"Cc : @PlasticDigits
mentioned in issue #381
@totdking please make an mr to the docs folder including the help/sec-i-prompt-pack.md
mentioned in issue #472
mentioned in merge request !1006
mentioned in commit
9ff4ea7b60mentioned in merge request !1007
MR made in !1007
When merged, this issue will be closed on my end @PlasticDigits
mentioned in commit
4b74383025