AML.T0061: LLM Prompt Self-Replication
An adversary may use a carefully crafted LLM Prompt Injection designed to cause the LLM to replicate the prompt as part of its output. This allows the prompt to propagate to other LLMs and persist on the system. The self-replicating prompt is typically paired with other malicious instructions (ex: LLM Jailbreak, LLM Data Leakage).
Standards mapping
Where this fits in a TurboPentest engagement
This weakness is not covered by the automated black-box pentest. IntegSec pentesters cover it in a manual engagement.
Frequently asked questions
What is AML.T0061 LLM Prompt Self-Replication?
An adversary may use a carefully crafted LLM Prompt Injection designed to cause the LLM to replicate the prompt as part of its output. This allows the prompt to propagate to other LLMs and persist on the system. The self-replicating prompt is typically paired with other malicious instructions (ex: LLM Jailbreak, LLM Data Leakage).
Which tactics does AML.T0061 belong to?
AML.T0061 maps to the Persistence tactic.
Does TurboPentest test for LLM Prompt Self-Replication?
This weakness is not covered by the automated black-box pentest. IntegSec pentesters cover it in a manual engagement.
Related MITRE ATLAS techniques
- Persistence, AI Attack StagingAML.T0018: Manipulate AI Model
- Resource Development, PersistenceAML.T0020: Poison Training Data
- PersistenceAML.T0070: RAG Poisoning
- PersistenceAML.T0080: AI Agent Context Poisoning
- Persistence, Defense EvasionAML.T0081: Modify AI Agent Configuration
- Initial Access, PersistenceAML.T0093: Prompt Infiltration via Public-Facing Application
About this reference
These security references are maintained by IntegSec, an offensive-security firm whose team holds CISSP, OSCP, and OSCE certifications and has run thousands of penetration tests. Content is kept current as tools, standards, and attack techniques evolve.
Find these issues before an attacker does
TurboPentest runs an agentic AI pentest against your target and reports findings with proof, from $99 per target.
Start a pentest