YARA rule 'agent_skill_prompt_injection_hidden_instructions': Prompt injection or hidden instructions embedded in AI agent skill text [agent_skills]
High
- Category
- YARA Match
- Content
iption: > Prompt injection and jailbreak detection pack. 16 compiled regex patterns across 3 severity levels (CRITICAL, HIGH, MEDIUM). Supports single-prompt and batch scanning modes. author: romainsantoli-web license: MIT metadata: openclaw: registry: ClawHub requires: - mcp-openclaw-extensions >= 3.0.0 tags: - security - prompt-injection - jailbreak - detection - llm-safety --- # firm-prompt-security-pack > ⚠️ Contenu généré par IA — validation humaine requise avant utilisation. ## Purpose Protects LLM-powered agents from prompt injection attacks and jailbreak attempts. Uses 16 compiled regex patterns to detect override instructions, ChatML injection, DAN-style jailbreaks, base64 evasion, and data exfiltration attempts. ## Tools (2) | Tool | Description | Mode | |------|-------------|------| | `openclaw_prompt_injection_check` | Scan a single prompt for injection patterns | Single | | `openclaw_prompt_injection_batch` | Scan multiple pro- Confidence
- 80% confidence
- Finding
- YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
