[
    {
        "id": "osp-27007",
        "type": "article-journal",
        "title": "pikit: A Composable Toolkit for Indirect Prompt Injection Research and Evaluation",
        "author": [
            {
                "family": "Ying",
                "given": "Zonghao"
            },
            {
                "family": "Wu",
                "given": "Xiangfan"
            },
            {
                "family": "Yang",
                "given": "Bo"
            },
            {
                "family": "Wu",
                "given": "Huiyu"
            },
            {
                "family": "Zheng",
                "given": "Xing"
            },
            {
                "family": "Cheng",
                "given": "Huangsheng"
            },
            {
                "family": "Shi",
                "given": "Xiaorong"
            },
            {
                "family": "Guo",
                "given": "Jing"
            }
        ],
        "URL": "https://omanscience.com/en/articles/pikit-a-composable-toolkit-for-indirect-prompt-injection-research-and-evaluation",
        "language": "en",
        "issued": {
            "date-parts": [
                [
                    2026
                ]
            ]
        },
        "abstract": "Indirect prompt injection embeds malicious instructions within external content retrieved by LLM-based agents, altering target behavior without user authorization. We introduce pikit, a research toolkit designed to systematically evaluate these threats across three core dimensions: attacks (13 methods), channels (16 carriers across text and file modes), and defenses (9 prevention strategies and 3 offline detection baselines). Built on a decorator-based registry, pikit enables seamless extension of custom components without modifying core code, while a unified craft() API composes arbitrary attacks and channels in a single call. We evaluated the toolkit on the pi coding agent powered by an anonymized LLM in a production-like environment. Benchmarking 9 prevention strategies against high-risk attacks yields a 71.8\\% relative reduction in attack success rate, with few\\_shot\\_warning and instruction\\_hierarchy providing the strongest protection. Offline detection baselines achieve perfect precision but low recall, demonstrating that heuristic detectors complement rather than replace prompt-level defenses. To ensure reproducibility, each run automatically logs full prompts, agent event traces, session transcripts, and verdict records. Our code is available at https://github.com/Tencent/AI-Infra-Guard/tree/main/Research/pikit."
    }
]