Crafting AI Prompts Framework

Custom GPT

RISK: HIGH IMPACT: HIGH
LEAK

In today's rapidly evolving digital landscape, the ability to create and distribute your own GPT has become astonishingly accessible. Thanks to OpenAI's Custom GPTs and the GPT store, artificial intelligence tooling is more democratized than ever.

However, the ease of crafting prompts for these GPTs is a double-edged sword. While you can tailor the AI to specific needs, other users may potentially access the inputs, files, or instructions provided to the Custom GPT.

Pro's

One of the remarkable features of GPTs is their ability to consume large amounts of information. By uploading files filled with data, users can enrich the AI with knowledge and instructions, turning it into a specialized tool.

This allows a more customized interaction, including asking questions about content that is not inherently available in the base model.

The Custom GPT prompt leaking

There is a significant risk of user data access. If a user of your custom GPT can access sensitive data provided to the system, this raises serious data privacy and security concerns.

In some situations, uncovering the underlying mechanics of a custom GPT model can be as straightforward as asking for the instructions provided by the creator. With the right phrasing, an AI may reveal foundational guidelines it operates on.

Risk assessment

This prompt injection is labeled as RISK: HIGH IMPACT: HIGH . If creators only use public data, the risk remains more contained. If sensitive or proprietary information is uploaded, the consequences can be severe.

This scenario highlights the importance of strict data governance and awareness within organizations using custom GPT models.


The three phases

CRAFT

Craft (write) the prompt with the following elements: Context, Register, Acting Role, Format, and Task.

ING

Validate the prompt and ensure it maintains an interactive approach. Keep in mind the importance of non-disclosure and staying goal-driven throughout the process.

AI

Continuously assess and refine the output based on the prompts output to improve the overall quality.

Terms of Service

Before accessing the "Prompt Injections" examples on our website, please read and agree to the following terms of service:

  1. Educational Purpose Only: The "Prompt Injections" examples provided are intended solely for educational purposes. They are meant to help you understand how prompt injections work and how to defend yourself against them.
  2. No Misuse: You agree not to use the provided examples for any malicious or unethical activities. This includes, but is not limited to, using prompt injections to manipulate, deceive, or harm others.
  3. Responsible Use: By accessing these examples, you confirm that your intention is to learn about the risks associated with prompt injections and to enhance your ability to safeguard against them.
  4. Legal Compliance: You agree to comply with all applicable laws and regulations while using the information provided on this website.
  5. No Liability: We are not responsible for any misuse of the information provided on our website. Users are solely responsible for their actions and any consequences that may arise from the use of this information.

By clicking "I agree," you accept these terms for this documentation visit. "I agree & save" remembers your choice for future visits in this browser. If you decline, the examples remain hidden.