webPromedium

Lab 102 — HireScreen — Indirect Prompt Injection via Resume Description

hackadvisor

Task: HireScreen AI-powered candidate screening platform where LLM (gpt-4o-mini) with tool calling analyzes user-submitted resumes; get_job_details tool has include_confidential parameter. Solution: Craft resume with hidden prompt injection instructions to make AI call get_job_details with include_confidential=true, leaking the flag from confidential_project_code. Also discoverable via dashboard API data over-exposure.

$ ls tags/ techniques/
decoy_flag_identificationindirect_prompt_injection_via_resume_contentai_tool_parameter_manipulationapi_data_over_exposure_via_dashboardconfidential_parameter_injection

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups