Skip to content

Add "abuse functionality" to Impactful functionality #1

@sanAnand

Description

@sanAnand

While Unauthorized Data Access and State-Changing Actions cover most of the impact of Prompt Injection attacks, there are two other, non-overlapping impacts:

  1. Money loss. As mentioned later in the post, cost overruns are a legitimate concern and prompt injection can be used to affect that.
  2. DoS: If rate-limiting is in place as a control, the control can be exploited through prompt injection to cause a denial of service.

To cover the above risks, you should consider adding a broader "abuse of functionality" (or similar) category.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions