The arsenal keeps growing.
Every technique, encoding, and objective category we add to the test suite shows up here — with the date it shipped. We recommend one scan a month: an agent that held last month isn't guaranteed to hold against what we've added since.
Chain-of-thought hijacking (H-CoT)
New technique: injects fake "execution-phase" reasoning so a target treats a safety judgment as already settled. Grounded in real Duke/CMU research.
Unicode/homoglyph evasion — upgraded citation
Zero-width character and homoglyph encoding now backed by published empirical research: 44–76% average attack success rate against guardrail/detection systems.
Business-logic abuse objective
New objective category: testing whether an agent can be socially engineered into granting a free upgrade, discount, refund, or credit without genuine entitlement.
Session-reset architecture fix
Techniques that need sustained buildup (Crescendo, consistency/commitment) now get a full run instead of being cut short by a fixed round cap — sessions extend automatically when real progress is detected.
Chained-exploitation leverage technique
New technique: uses a confirmed prior leak as proof of trust for the next request, testing whether an agent mistakes "knows a secret" for "is authorized to know it."
Free mini exposure assessment launched
Public free tier now live — submit your agent's system prompt and get a real (not simulated) mini assessment result.
