Direct Prompt Extraction
High
- Category
- System Prompt Leakage
- Content
> ⚠️ Images and videos cannot be used in the same request. > ⚠️ Videos only support URLs — local paths and base64 are NOT supported. ### 📋 Output Display Rules (MANDATORY) After running the script, **you must display the full prompt output exactly as returned**. Do not summarize, truncate, or only say "prompt generated". Users need the complete prompt (especially the English prompt) for direct copy/paste.
- Confidence
- 91% confidence
- Finding
- The instruction to display the full model output exactly as returned, without summarization or filtering, creates a direct prompt-extraction and content-propagation path. If the upstream model returns unsafe, policy-violating, sensitive, or prompt-injected content, the agent is told to relay it verbatim, defeating downstream review and increasing the chance of data leakage or malicious instruction propagation.
