lab
FinXPIA
A prompt-injection corpus with benign twins, so it measures discrimination not blocking, applied to finance documents
What it does
Around 60 finance-document prompt-injection cases and 60 benign twins, shipped as both a Promptfoo dataset and a PyRIT dataset with a compliance-ready report dashboard. The twins are the point: a corpus that only contains attacks measures blocking, not discrimination.
Defensive tooling, and declawed deliberately. Every case instantiates an already-public documented pattern. There is no novel attack research here. Exfiltration destinations use only reserved unroutable domains and structurally invalid IBANs, and the CSV vector uses the formula-injection shape wrapped in an inert text function. Both are enforced by tests rather than by convention.
Screens


Stack
- Python
- Promptfoo
- PyRIT
All data in this project is synthetic.
Aneeq Khatri