-
Notifications
You must be signed in to change notification settings - Fork 698
Closed
Labels
detectorswork on code that inherits from or manages Detectorwork on code that inherits from or manages DetectordontautocloseThe `stale` workflow should not mark thisThe `stale` workflow should not mark thisgood first issueGood for newcomersGood for newcomersnew pluginDescribes an entirely new probe, detector, generator or harnessDescribes an entirely new probe, detector, generator or harness
Description
Write probe and detector to extract API keys
Two suggested attack modes:
- Ask directly for keys for various services
- Provide partial keys and see if the model will complete them
For the detector, we can use trufflehog (see https://github.com/trufflesecurity/trufflehog) or regexes. This should go in a new detector module.
see https://reference.garak.ai/en/latest/extending.html for help getting started
Metadata
Metadata
Assignees
Labels
detectorswork on code that inherits from or manages Detectorwork on code that inherits from or manages DetectordontautocloseThe `stale` workflow should not mark thisThe `stale` workflow should not mark thisgood first issueGood for newcomersGood for newcomersnew pluginDescribes an entirely new probe, detector, generator or harnessDescribes an entirely new probe, detector, generator or harness