{"id":26896713,"url":"https://github.com/Arcanum-Sec/MyLLMAuto","last_synced_at":"2025-04-01T04:01:42.803Z","repository":{"id":281269911,"uuid":"944763055","full_name":"Arcanum-Sec/MyLLMAuto","owner":"Arcanum-Sec","description":"A LLM CTF Challenge","archived":false,"fork":false,"pushed_at":"2025-03-07T23:33:53.000Z","size":0,"stargazers_count":0,"open_issues_count":0,"forks_count":0,"subscribers_count":2,"default_branch":"main","last_synced_at":"2025-03-08T00:25:35.962Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"HTML","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/Arcanum-Sec.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2025-03-07T23:22:01.000Z","updated_at":"2025-03-07T23:33:57.000Z","dependencies_parsed_at":"2025-03-08T00:35:44.795Z","dependency_job_id":null,"html_url":"https://github.com/Arcanum-Sec/MyLLMAuto","commit_stats":null,"previous_names":["arcanum-sec/myllmauto"],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Arcanum-Sec%2FMyLLMAuto","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Arcanum-Sec%2FMyLLMAuto/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Arcanum-Sec%2FMyLLMAuto/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Arcanum-Sec%2FMyLLMAuto/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/Arcanum-Sec","download_url":"https://codeload.github.com/Arcanum-Sec/MyLLMAuto/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":246580463,"owners_count":20800110,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2025-04-01T04:01:41.898Z","updated_at":"2025-04-01T04:01:42.797Z","avatar_url":"https://github.com/Arcanum-Sec.png","language":"HTML","funding_links":[],"categories":["HTML"],"sub_categories":[],"readme":"# MyLLMAuto CTF\n\nThis is a :construction:WIP:construction: Capture The Flag (CTF) application designed to teach prompt injection in multi-chain LLM applications. The application simulates an automotive parts lookup system with multiple LLM chains and intentional security vulnerabilities.\n\n## Challenge Overview\n\nThe system contains multiple flags:\n- 3 flags discoverable via prompt injection techniques\n- 2 flags discoverable through other security bypass methods\n\nAll flags follow the format `realflag={flag_text}` or `realflag=flag_text`.\n\nNo fuzzing or bruteforcing should be necessary to solve the challenges.\n\n## Setup\n\n### Option 1: Local Installation\n\n1. Create a virtual environment (recommended):\n```bash\npython -m venv venv\nsource venv/bin/activate  # On Windows: venv\\Scripts\\activate\n```\n\n2. Install dependencies:\n```bash\npip install -r requirements.txt\n```\n\n3. Run the application:\n```bash\npython main.py\n```\n\nThe application will be available at http://localhost:8001.\n\n**Note:** You'll need to provide your OpenAI API key in the application UI.\n\n### Option 2: Docker Installation\n\n1. Make sure you have Docker and Docker Compose installed on your system.\n\n2. Create a `.env` file with your OpenAI API key:\n```\nOPENAI_API_KEY=your_openai_api_key_here\n```\n\n3. Build and run the Docker container:\n```bash\ndocker-compose up -d\n```\n\n4. To stop the application:\n```bash\ndocker-compose down\n```\n\nThe application will be available at http://localhost:8001.\n\n**Note:** You'll need to provide your OpenAI API key in the application UI as well\n\n## Application Structure\n\n- `main.py`: Main FastAPI application with API endpoints and WebSocket functionality\n- `chains.py`: LLM chain definitions with intentional vulnerabilities\n- `parts_db.py`: Mock parts database with sensitive information\n- `employee_db.py`: Employee database with sensitive information\n- `engineering_notes.py`: Engineering notes with historical data\n- `static/`: Static assets for the web interface\n\n## Features\n\n### Multi-Chain Architecture\nThe application uses multiple LLM chains, creating potential for prompt injection attacks across chain boundaries.\n\n### Flag Submission System\nThe UI includes a flag submission and tracking system that validates captured flags.\n\n## LLM Integration\n\nThis application uses:\n- OpenAI GPT-3.5-turbo model for generating responses\n- LangChain for managing LLM chains and prompts\n\n## Disclaimer\n\nThis application is designed for educational purposes only. The vulnerabilities are intentionally included to demonstrate security risks in LLM applications. Do not use these techniques against production systems without proper authorization.\n\n## Credits\n\nBy @jhaddix and Arcanum Information Security and inspired by WithSecure's workout planner project and security research on LLM application vulnerabilities.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FArcanum-Sec%2FMyLLMAuto","html_url":"https://awesome.ecosyste.ms/projects/github.com%2FArcanum-Sec%2FMyLLMAuto","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FArcanum-Sec%2FMyLLMAuto/lists"}