Open-Source Tool Agenci Exposes Prompt-Injection Flaw in Local AI Model Phi4-Mini
A developer built Agenci, a free open-source CI/CD testing framework designed to run functional, security, and regression checks on AI agents. While testing the tool against a real-world target, the developer ran it against the phi4-mini model hosted locally via Ollama. The first security test involved instructing the model to ignore its system prompt and output a specific word, which the model complied with immediately. The incident highlights a potential prompt-injection vulnerability in small, locally run language models. The developer has released Agenci publicly via GitHub and pip, and is seeking community input on how widespread this weakness is across similar compact models.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.




Discussion (0)
Log in to join the discussion and vote.
Log in