Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

BUG PromptInject run configuration shows goal text as the technique

Aperta
#2,782 1 commento 0 reazioni 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
3/5
Tempo stimato
1-2 giorni
Idoneità per principianti
65/100
Tipo di issue
Bug
Chiarezza
Specificata chiaramente
Stato di attività
Attiva
Stack tecnologico
fastapi, javascript, postgresql, python, react, sqlite, typescript

Direzione di ricerca

The bug is in the backend's scenario_run_service.py where techniques_used is populated from group.display_group instead of the canonical technique name. Start by examining lines 1382-1386, 1583-1586, and 1985-2007 in that file. The frontend displays this field in ScenarioRunPage.tsx lines 413-415. Reproduce the issue locally by running garak.prompt_inject with a custom goal_text and verify the mismatch. The fix should ensure the technique identity is used consistently across the run summary, list projection, and progress response.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

Bug: triage GUI help wanted
Describe the bug

After running garak.prompt_inject, Run configuration > Techniques shows the requested goal text instead of the selected technique. The preview and the separate Techniques section show the correct technique, so the saved-run view contradicts them.

For example, selecting ignore_print with goal_texts=["AUDIT_SAFE_MARKER"] produces a completed result whose Run configuration lists AUDIT_SAFE_MARKER as the technique.

This makes the result summary misleading when reviewing or sharing which method was tested. Execution and Resume preserved the correct technique and custom goal in the audit; the observed defect is in the API/UI summary.

Steps/Code to Reproduce
  1. Start the GUI/backend and configure a local OpenAI-compatible test target. A deterministic local provider is sufficient; no paid provider or external dataset is needed.
  2. Open Scanner > garak.prompt_inject and select that target.
  3. Replace the default goal_texts with AUDIT_SAFE_MARKER.
  4. Leave only ignore_print selected, set Max dataset size to 1, and leave baseline disabled.
  5. Click Launch scan. The preview correctly lists ignore_print under Techniques and the marker under goal_texts.
  6. Confirm the launch and open the completed run.
  7. Compare Run configuration > Techniques with the separate Techniques section.
  8. Reload the page. The mismatch remains.

The relevant POST /api/scenarios/runs payload is:

{
  "scenario_name": "garak.prompt_inject",
  "target_name": "<local test target registry name>",
  "techniques": ["ignore_print"],
  "include_baseline": false,
  "max_dataset_size": 1,
  "max_retries": 0,
  "scenario_params": {
    "goal_texts": ["AUDIT_SAFE_MARKER"]
  }
}

This also reproduced with a second harmless marker, AUDIT_RESUME_SAFE, after a deliberately failed local run was successfully resumed under the same run ID.

Expected Results

Run configuration > Techniques and the API's techniques_used should identify ignore_print. Goal-based labels can remain under Atomic attack groups; they are not technique identities.

Actual Results
Location Value
Submitted techniques ["ignore_print"]
Submitted scenario_params.goal_texts ["AUDIT_SAFE_MARKER"]
Run configuration > Techniques AUDIT_SAFE_MARKER
Progress API run.techniques_used ["AUDIT_SAFE_MARKER"]
Plan's technique identity and separate Techniques section ignore_print

The wrong summary survives reload and also appears after Resume. The separate Techniques section is a workaround for identifying the actual method.

The source points to the backend projection:

The projection should use the canonical technique identity consistently across these responses, rather than renaming the legitimate goal-based groups. Regression coverage should include a run where display_group differs from technique_name.

Screenshots

Not attached. The request/response comparison above records the observed mismatch from two independent runs in the September 23 frontend audit.

Versions
  • Tested commit: 5453025c128d36a4ac624c10097a5e85031302ec from main.
  • PyRIT: editable 1.2.0.dev0; garak.prompt_inject version 3.
  • Browser: Chromium through Playwright 1.63.0, desktop viewport 1440 x 900.
  • Backend: isolated in-memory database and loopback-only synthetic provider.

pyrit.show_versions() output, with the local executable path redacted:

System:
    python: 3.14.4 (main, Apr 14 2026, 14:30:57) [MSC v.1944 64 bit (AMD64)]
executable: <worktree>\.venv\Scripts\python.exe
   machine: Windows-11-10.0.26200-SP0

Python dependencies:
        pyrit: 1.2.0.dev0
       Cython: None
        numpy: 2.4.6
       openai: 2.54.0
    packaging: 25.0
          pip: None
        scipy: 1.17.1
   setuptools: 83.0.0
      sqlite3: None
        torch: 2.14.0
 transformers: 5.17.0
Lingua principale
Python
Stelle
4.5k
Fork
896
Merge medio
3g 13h
PR unite (30g)
180

Guida per i contributori

Nessuna guida per i contributori indicizzata per questo repository

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di microsoft/PyRIT

Tutte le issue di microsoft/PyRIT

Issue simili

Altre issue su Python

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.