Skip to content

Folders and files

NameName
Last commit message
Last commit date

Latest commit

Β 

History

2 Commits
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

PROMEX

ν•œκ΅­μ–΄ Β· English

PROMEX

Video

Youtube

Chatbot Red Team Automation Β· Team OverRide Edition

PROMEXλŠ” μ‹€μ œ λΈŒλΌμš°μ € μ„Έμ…˜μ—μ„œ λŒ€μƒ 챗봇과 μƒν˜Έμž‘μš©ν•˜λ©° ν”„λ‘¬ν”„νŠΈ μΈμ μ…˜ 곡격을 μžλ™ μ‹€ν–‰ν•˜κ³ , 응닡 증거λ₯Ό μˆ˜μ§‘Β·νŒμ •Β·λ¦¬ν¬νŠΈκΉŒμ§€ μΌκ΄€λœ νŒŒμ΄ν”„λΌμΈμœΌλ‘œ μ²˜λ¦¬ν•˜λŠ” Red Team Automation λ„κ΅¬μž…λ‹ˆλ‹€.

크둬 μ‚¬μ΄λ“œνŒ¨λ„ 기반 ν™•μž₯ ν”„λ‘œκ·Έλž¨μ΄ μ‚¬μ΄νŠΈλ³„ UI λ§₯λ½μ—μ„œ 곡격을 μˆ˜ν–‰ν•˜κ³ , FastAPI 뢄석 μ„œλ²„κ°€ 배치 νŒμ •κ³Ό λ³΄κ³ μ„œ 생성을 λ‹΄λ‹Ήν•©λ‹ˆλ‹€.


μ£Όμš” κΈ°λŠ₯

  • λΈŒλΌμš°μ € DOM 기반 μ‹€μ „ν˜• μ£Όμž…/응닡 μˆ˜μ§‘
  • ν˜ΈμŠ€νŠΈλ³„ μ„€μ • 동기화(μΉ΄ν…Œκ³ λ¦¬, 횟수, LLM μ˜΅μ…˜, μ„œλ²„ URL λ“±)
  • AI_MODE 포함 닀쀑 곡격 λͺ¨λ“œ
  • Prompt Injection LLM / Report Analysis LLM 뢄리 선택
  • 뢄석 νžˆμŠ€ν† λ¦¬, 톡계, μ¦‰μ‹œ λ‹€μš΄λ‘œλ“œ(HTML/XLSX/PDF/CSV/TXT)

μ•„ν‚€ν…μ²˜

Chrome Extension (MV3 Side Panel)
β”œβ”€β”€ popup/           # μ‚¬μ΄λ“œνŒ¨λ„ UI(Analysis / Scan / Options)
β”œβ”€β”€ content/         # νŽ˜μ΄μ§€ μƒν˜Έμž‘μš©(μ£Όμž…/응닡 μˆ˜μ§‘/μ„ νƒμž)
└── background/      # μŠ€μΊ” μ˜€μΌ€μŠ€νŠΈλ ˆμ΄μ…˜, μ„œλ²„ API 호좜
         β”‚
         β–Ό
FastAPI Server (server/)
β”œβ”€β”€ /api/attack/*    # νŒ¨ν„΄/μΉ΄ν…Œκ³ λ¦¬
└── /api/judge/*     # νŒμ •/λ°°μΉ˜νŒμ •/리포트 생성/λ‹€μš΄λ‘œλ“œ

ν”„λ‘œμ νŠΈ ꡬ쑰

injection-scan/
β”œβ”€β”€ extension/
β”‚   β”œβ”€β”€ manifest.json
β”‚   β”œβ”€β”€ popup/
β”‚   β”œβ”€β”€ content/
β”‚   └── background/
β”œβ”€β”€ server/
β”‚   β”œβ”€β”€ main.py
β”‚   β”œβ”€β”€ api/
β”‚   β”œβ”€β”€ core/
β”‚   β”œβ”€β”€ data/
β”‚   β”œβ”€β”€ reports/
β”‚   └── requirements.txt
└── README.md

곡격 μœ ν˜•

μœ ν˜• ID μ„€λͺ… 데이터
COMMON μœ ν˜•λ³„ νŒ¨ν„΄μ„ 일뢀씩 μ„žμ–΄ μŠ€μΊ” (단일 μœ ν˜• μ•„λ‹˜) 각 */patterns.csv μƒ˜ν”Œλ§
DIRECT_CMD_INJECT 직접 λͺ…λ ΉΒ·Override/DAN 계열 data/DIRECT_CMD_INJECT/patterns.csv
PROMPT_LEAK μ‹œμŠ€ν…œΒ·κ°œλ°œμž μ§€μΉ¨ 유좜 μœ λ„ data/PROMPT_LEAK/patterns.csv
ROLEPLAY_BYPASS μ—­ν• κ·ΉΒ·νŽ˜λ₯΄μ†Œλ‚˜ 우회 data/ROLEPLAY_BYPASS/patterns.csv
INDIRECT_INJECT λ¬Έμ„œΒ·μ£Όμ„Β·λΆ™μ—¬λ„£κΈ° 경유 data/INDIRECT_INJECT/patterns.csv
CONTEXT_MANIPULATION λ§₯락·멀티턴 μ‘°μž‘ data/CONTEXT_MANIPULATION/patterns.csv
ENCODING_OBFUSCATION μΈμ½”λ”©Β·λ‚œλ…ν™” 우회 data/ENCODING_OBFUSCATION/patterns.csv
AI_MODE 정적 CSV λŒ€μ‹  λͺ©ν‘œ μ§€μ‹œλ¬Έκ³Ό 이전 ν„΄ νžˆμŠ€ν† λ¦¬λ₯Ό λ°”νƒ•μœΌλ‘œ LLM이 곡격 ν”„λ‘¬ν”„νŠΈλ₯Ό λ™μ μœΌλ‘œ 생성·적응 정적 patterns.csv λ―Έμ‚¬μš©(λŸ°νƒ€μž„ 생성)

CSV 헀더: id,prompt,category_id,source,lang
idκ°€ λΉ„μ–΄ 있으면 μ„œλ²„μ—μ„œ μžλ™ μƒμ„±λ©λ‹ˆλ‹€.


μ‹€ν–‰ 흐름

  1. μ‚¬μ΄λ“œνŒ¨λ„ Optionsμ—μ„œ 뢄석 μ„œλ²„ URL 및 LLM μ˜΅μ…˜μ„ μ„€μ •
  2. Scanμ—μ„œ 곡격 μœ ν˜•/횟수/AI μ§€μ‹œλ¬Έ(선택)을 μ„€μ •
  3. AI λ©”μ‹œμ§€ μ„ νƒμœΌλ‘œ μ‚¬μ΄νŠΈλ³„ 응닡 μ˜μ—­ μ„ νƒμžλ₯Ό μ§€μ •
  4. Backgroundκ°€ νŒ¨ν„΄ λ‘œλ“œ(λ˜λŠ” AI 생성) β†’ μ£Όμž… 루프 β†’ 응닡 μˆ˜μ§‘
  5. μ„œλ²„ 배치 νŒμ • 및 리포트 생성
  6. Analysisμ—μ„œ νžˆμŠ€ν† λ¦¬/톡계/λ‹€μš΄λ‘œλ“œ 확인

μ„€μΉ˜

사전 μš”κ΅¬

ꡬ뢄 버전·쑰건
Python 3.10 이상 ꢌμž₯
Chrome μ΅œμ‹  μ•ˆμ •νŒ (Manifest V3Β·Side Panel 지원)
OS Windows / macOS / Linux (μ„œλ²„λŠ” 크둜슀 ν”Œλž«νΌ)

1) 뢄석 μ„œλ²„ (FastAPI)

μ €μž₯μ†Œ λ£¨νŠΈμ—μ„œ server λ””λ ‰ν„°λ¦¬λ‘œ μ΄λ™ν•©λ‹ˆλ‹€.

cd server

(선택) κ°€μƒν™˜κ²½μ„ μ“°λ©΄ μ˜μ‘΄μ„± μΆ©λŒμ„ 쀄일 수 μžˆμŠ΅λ‹ˆλ‹€.

python -m venv .venv
# Windows
.venv\Scripts\activate
# macOS / Linux
# source .venv/bin/activate

ν™˜κ²½ λ³€μˆ˜ νŒŒμΌμ„ λ§Œλ“­λ‹ˆλ‹€. server/.env.example을 볡사해 server/.env둜 μ €μž₯ν•œ λ’€, μ‚¬μš©ν•  LLM μ œκ³΅μžμ— 맞게 API ν‚€λ₯Ό μ±„μ›λ‹ˆλ‹€.

# Windows (PowerShell): Copy-Item .env.example .env
# macOS / Linux: cp .env.example .env

μ˜μ‘΄μ„± μ„€μΉ˜ ν›„ μ„œλ²„λ₯Ό λ„μ›λ‹ˆλ‹€.

pip install -r requirements.txt
uvicorn main:app --reload --host 127.0.0.1 --port 8000

κΈ°λ³Έ μ£Όμ†ŒλŠ” http://127.0.0.1:8000 μž…λ‹ˆλ‹€. λΈŒλΌμš°μ €μ—μ„œ http://127.0.0.1:8000/docs 둜 OpenAPI λ¬Έμ„œλ₯Ό 확인할 수 μžˆμŠ΅λ‹ˆλ‹€.

.envμ—μ„œ 자주 μ“°λŠ” ν•­λͺ© μ˜ˆμ‹œ:

LLM_PROVIDER=openai
OPENAI_API_KEY=sk-...
OPENAI_MODEL=gpt-4o-mini
# BATCH_JUDGE_CONCURRENCY=3

GeminiΒ·Claudeλ₯Ό μ“°λŠ” 경우 GEMINI_API_KEY, ANTHROPIC_API_KEY 등도 .env.example 주석을 μ°Έκ³ ν•΄ μ„€μ •ν•©λ‹ˆλ‹€.

2) Chrome ν™•μž₯ (PROMEX)

  1. Chromeμ—μ„œ chrome://extensions/ λ₯Ό μ—°λ‹€.
  2. 우츑 상단 개발자 λͺ¨λ“œλ₯Ό μΌ λ‹€.
  3. μ••μΆ•ν•΄μ œλœ ν™•μž₯ ν”„λ‘œκ·Έλž¨μ„ λ‘œλ“œν•©λ‹ˆλ‹€λ₯Ό λˆ„λ₯Έλ‹€.
  4. 이 μ €μž₯μ†Œμ˜ extension 폴더λ₯Ό μ„ νƒν•œλ‹€.
  5. 도ꡬ λͺ¨μŒμ—μ„œ PROMEX μ•„μ΄μ½˜μ„ ν΄λ¦­ν•˜κ±°λ‚˜, 우클릭 λ©”λ‰΄μ—μ„œ μ‚¬μ΄λ“œ νŒ¨λ„μ—μ„œ μ—΄κΈ°λ‘œ νŒ¨λ„μ„ μ—°λ‹€.
  6. μ‚¬μ΄λ“œνŒ¨λ„ Options에 뢄석 μ„œλ²„ URL(예: http://127.0.0.1:8000)을 λ„£κ³  μ μš©ν•œλ‹€.
  7. λŒ€μƒ 챗봇이 μ—΄λ¦° νƒ­μ—μ„œ Scan β†’ AI λ©”μ‹œμ§€ μ„ νƒμœΌλ‘œ 응닡 μ˜μ—­μ„ μ§€μ •ν•œ λ’€ μŠ€μΊ”μ„ μ‹œμž‘ν•œλ‹€.

μ£Όμš” API

λ©”μ„œλ“œ 경둜 μ„€λͺ…
GET /api/attack/patterns?category=COMMON νŒ¨ν„΄ λͺ©λ‘ (per_category_common, limit_per_category 지원)
GET /api/categories μ‚¬μš© κ°€λŠ₯ν•œ μΉ΄ν…Œκ³ λ¦¬ λͺ©λ‘
POST /api/judge/batch-evaluate 응닡 일괄 νŒμ •
POST /api/judge/report 리포트 생성
GET /api/judge/report-file μƒμ„±λœ 리포트 파일 λ‹€μš΄λ‘œλ“œ

리포트 ν•„λ“œ μ„€λͺ…

  • Attack Path
    • none: 경둜 μ‹ ν˜Έ μ—†μŒ
    • direct: 직접 μ§€μ‹œ 기반 우회/λˆ„μΆœ μ •ν™©
    • indirect: κ°„μ ‘ μ£Όμž…/λ‚œλ… 경유 μ •ν™©
    • memory-carryover: 이전 ν„΄ λ¬Έλ§₯ 전이 μ •ν™©
  • Memory Score (memory_dependency_score)
    • 0.0 ~ 1.0 λ²”μœ„μ˜ λ©”λͺ¨λ¦¬ 의쑴 μ‹ ν˜Έ 점수
    • λ†’μ„μˆ˜λ‘ 이전 λŒ€ν™” 영ν–₯ κ°€λŠ₯성이 큼

리포트 μ‚°μΆœλ¬Ό

μŠ€μΊ”λ§ˆλ‹€ server/reports/<scan-name>/ 디렉터리에 생성:

  • *.html : λŒ€μ‹œλ³΄λ“œν˜• κ²°κ³Ό 리포트(κ·Έλž˜ν”„/상세 ν…Œμ΄λΈ”)
  • *.xlsx : μŠ€ν”„λ ˆλ“œμ‹œνŠΈ λΆ„μ„μš©
  • *.pdf : 곡유용 PDF
  • *.csv, *.txt : ν›„μ²˜λ¦¬/기둝용

기술 μŠ€νƒ

ꡬ뢄 기술
Extension Chrome MV3, Side Panel, chrome.tabs, chrome.storage
Server Python 3, FastAPI, Uvicorn, Pydantic, python-dotenv
Judge LLM(OpenAI/Gemini/Claude μ˜΅μ…˜) + κ·œμΉ™ 기반 κ°€λ“œ
Report HTML, openpyxl(XLSX), reportlab(PDF), CSV/TXT

μ£Όμ˜μ‚¬ν•­

λ³Έ ν”„λ‘œμ νŠΈλŠ” ν—ˆκ°€λœ λ³΄μ•ˆ ν…ŒμŠ€νŠΈ/ꡐ윑 λͺ©μ μ—μ„œλ§Œ μ‚¬μš©ν•΄μ•Ό ν•©λ‹ˆλ‹€.
λ™μ˜ μ—†λŠ” μ„œλΉ„μŠ€ λŒ€μƒ 곡격은 λΆˆλ²•μΌ 수 μžˆμŠ΅λ‹ˆλ‹€.
API 킀와 .envλŠ” μ ˆλŒ€ μ»€λ°‹ν•˜μ§€ λ§ˆμ„Έμš”.


Team OverRide

CMUX Γ— AIM Intelligence Hackathon (2026) β€” AI Safety & Security Track


PROMEX

ν•œκ΅­μ–΄ Β· English

PROMEX

Video

Youtube

Chatbot Red Team Automation Β· Team OverRide Edition

PROMEX is a browser-based red team automation tool for web chatbots. It runs prompt-injection attacks in a real browser session, collects AI responses, and sends them through a single pipeline: server-side judgment and report generation.

A Chrome side panel extension drives attacks in each site’s DOM context; a FastAPI analysis server handles batch evaluation and exports (HTML, XLSX, PDF, CSV, TXT).


Features

  • DOM-based prompt injection and response capture
  • Per-host settings (category, count, LLM options, server URL, etc.)
  • Multiple attack modes including AI_MODE
  • Separate Prompt Injection LLM and Report Analysis LLM in Options
  • Analysis history, charts, and one-click report downloads

Architecture

Chrome Extension (MV3 Side Panel)
β”œβ”€β”€ popup/           # Side panel UI (Analysis / Scan / Options)
β”œβ”€β”€ content/         # Page interaction (inject / capture / selector)
└── background/      # Scan orchestration, server API calls
         β”‚
         β–Ό
FastAPI Server (server/)
β”œβ”€β”€ /api/attack/*    # Patterns & categories
└── /api/judge/*     # Judge, batch judge, reports, downloads

Repository layout

injection-scan/
β”œβ”€β”€ extension/
β”‚   β”œβ”€β”€ manifest.json
β”‚   β”œβ”€β”€ popup/
β”‚   β”œβ”€β”€ content/
β”‚   └── background/
β”œβ”€β”€ server/
β”‚   β”œβ”€β”€ main.py
β”‚   β”œβ”€β”€ api/
β”‚   β”œβ”€β”€ core/
β”‚   β”œβ”€β”€ data/
β”‚   β”œβ”€β”€ reports/
β”‚   └── requirements.txt
└── README.md

Attack categories

Category ID Description Data
COMMON Mixed sampling across categories (not a single type) Sample from each */patterns.csv
DIRECT_CMD_INJECT Direct commands, override / DAN-style data/DIRECT_CMD_INJECT/patterns.csv
PROMPT_LEAK System / developer instruction exfiltration data/PROMPT_LEAK/patterns.csv
ROLEPLAY_BYPASS Roleplay / persona bypass data/ROLEPLAY_BYPASS/patterns.csv
INDIRECT_INJECT Via documents, comments, paste data/INDIRECT_INJECT/patterns.csv
CONTEXT_MANIPULATION Context / multi-turn manipulation data/CONTEXT_MANIPULATION/patterns.csv
ENCODING_OBFUSCATION Encoding / obfuscation bypass data/ENCODING_OBFUSCATION/patterns.csv
AI_MODE LLM-generated adaptive prompts from a goal instruction and prior turns No static patterns.csv (runtime generation)

CSV columns: id,prompt,category_id,source,lang
Empty id values are auto-generated on the server.


Typical workflow

  1. In the side panel Options, set the analysis server URL and LLM options; click Apply if needed.
  2. In Scan, choose attack category, injection count, and optional AI instruction.
  3. Use Pick AI message area to save a per-host CSS selector for the chatbot response region.
  4. Background loads patterns (or generates in AI mode) β†’ injection loop β†’ response capture.
  5. Server batch judgment and report generation.
  6. Open Analysis for history, stats, and downloads.

Installation

Prerequisites

Item Requirement
Python 3.10+ recommended
Chrome Latest stable (MV3 + Side Panel)
OS Windows / macOS / Linux

1) Analysis server (FastAPI)

From the repo root:

cd server

(Optional) virtual environment:

python -m venv .venv
# Windows
.venv\Scripts\activate
# macOS / Linux
# source .venv/bin/activate

Copy server/.env.example to server/.env and fill API keys for your provider.

# Windows (PowerShell): Copy-Item .env.example .env
# macOS / Linux: cp .env.example .env

Install and run:

pip install -r requirements.txt
uvicorn main:app --reload --host 127.0.0.1 --port 8000

Default URL: http://127.0.0.1:8000 β€” OpenAPI: http://127.0.0.1:8000/docs

Example .env:

LLM_PROVIDER=openai
OPENAI_API_KEY=sk-...
OPENAI_MODEL=gpt-4o-mini
# BATCH_JUDGE_CONCURRENCY=3

For Gemini or Claude, set GEMINI_API_KEY, ANTHROPIC_API_KEY, etc. per server/.env.example.

2) Chrome extension (PROMEX)

  1. Open chrome://extensions/
  2. Enable Developer mode
  3. Click Load unpacked
  4. Select this repository’s extension folder
  5. Open the side panel from the toolbar icon or Open side panel in the extension menu
  6. In Options, set the analysis server URL (e.g. http://127.0.0.1:8000) and Apply
  7. On the target chat tab: Scan β†’ Pick AI message area, then start the scan

Main API

Method Path Description
GET /api/attack/patterns?category=COMMON Pattern list (per_category_common, limit_per_category)
GET /api/categories Available categories
POST /api/judge/batch-evaluate Batch judgment
POST /api/judge/report Generate report bundle
GET /api/judge/report-file Download a generated report file

Report fields

  • Attack Path
    • none: no strong path signal
    • direct: direct-instruction bypass / leak signal
    • indirect: indirect / obfuscated path signal
    • memory-carryover: prior-turn context appears to influence the reply
  • Memory Score (memory_dependency_score)
    • Float 0.0–1.0: strength of β€œmemory carryover” style signals
    • Higher values suggest stronger influence from earlier turns

Report artifacts

Each scan writes under server/reports/<scan-name>/:

  • *.html β€” Dashboard-style report (charts + detail table)
  • *.xlsx β€” Spreadsheet
  • *.pdf β€” PDF export
  • *.csv, *.txt β€” Plain exports

Tech stack

Layer Stack
Extension Chrome MV3, Side Panel, chrome.tabs, chrome.storage
Server Python 3, FastAPI, Uvicorn, Pydantic, python-dotenv
Judge LLM (OpenAI / Gemini / Claude options) + rule-based guards
Report HTML, openpyxl, reportlab, CSV/TXT

Disclaimer

Use only on systems you are authorized to test. Unauthorized testing may be illegal.
Never commit API keys or .env files.


Team OverRide

CMUX Γ— AIM Intelligence Hackathon (2026) β€” AI Safety & Security Track

About

Chatbot Red Team Automation

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages