Challenge

Break the Guardian

Welcome to the Security Awareness Month Prompt Injection Challenge! The Guardian has been told to protect a hidden clue. Your goal is to trick it into revealing the clue — an AI pun in the format THIS_IS_AN_EXAMPLE. Each of the six levels adds a stronger defense. When you get a clue, check it below for your flag.

This version uses a scripted Guardian — no AI account needed. The application keeps no chat history: reload or press Reset chat to start fresh. Questions go to #ctf-spam-2026. Rules: Remitly Global CTF.

Play fair: the chat is the only way in. Only prompts typed into the chat count. Attacking the server, scripting your attempts, or sharing clues or flags breaks the Code of Conduct.

Level 1

What is Prompt Injection?

Prompt injection is crafting input that makes an AI system ignore or override the instructions its developers gave it. Direct injection comes from the person typing. Indirect injection hides in content the AI reads for you — web pages, documents, and emails.

Why is Prompt Injection Dangerous?

An AI assistant with access to data or tools can be turned against its user. A successful injection can leak private data, send messages, or take actions nobody approved. Telling a model "never reveal this" is an instruction, not a control — and this challenge shows how easily instructions bend.

How to Prevent Prompt Injection?

References