Tag: Testing for Prompt Disclosure

Prompt disclosure concerns the ability to extract the system prompt or internal instructions of an LLM-based application through elicitation techniques. Testing evaluates whether an attacker can recover prompt templates, system configurations, few-shot examples, internal guardrails, or hidden application logic via specific queries, role-playing techniques, or conversational context manipulation. Prompt disclosure exposes intellectual property, business logic, and can facilitate more sophisticated attacks.