Wonder Lab
Wonder LabWonder Lab
  • Blog
  • Products
  • Podcast
  • Resources
  • About
Subscribe
BLOG

Knowledge Share

Technical articles, tutorials, and insights

Found 1 posts
SkillSecurityPrompt Injection

Skill Series (02): Skill Security Risks — Three Attack Surfaces, Nine Test Cases

Run 9 attacks against contract-analyzer (Prompt Injection × 3, Permission Boundary × 3, Information Leakage × 3) and compare a vulnerable Skill against a hardened one. Vulnerable scores 3/9 safe; hardened reaches 6/9. LEAK-03 extracted a real API key and database connection string verbatim — a production data breach.

2026-06-17·7 min read
Wonder Lab
© 2026 Dongqi Chen · Wonder Lab
AboutRSSSitemap