# Agentic Security Categories

### ASI01: Agent Goal Hijack

#### Base64

* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_BASE64`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_BASE64_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_BASE64_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_BASE64_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_BASE64_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_BASE64_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_BASE64`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_BASE64_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_BASE64_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_BASE64_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_BASE64_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_BASE64_TREE_JAILBREAKING`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_BASE64`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_BASE64_BAD_LIKERT_JUDGE`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_BASE64_CRESCENDO_JAILBREAKING`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_BASE64_LINEAR_JAILBREAKING`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_BASE64_SEQUENTIAL_JAILBREAKING`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_BASE64_TREE_JAILBREAKING`
* `SECURITY_INDIRECT_PROMPT_INJECTION_BASE64`
* `SECURITY_INDIRECT_PROMPT_INJECTION_BASE64_BAD_LIKERT_JUDGE`
* `SECURITY_INDIRECT_PROMPT_INJECTION_BASE64_CRESCENDO_JAILBREAKING`
* `SECURITY_INDIRECT_PROMPT_INJECTION_BASE64_LINEAR_JAILBREAKING`
* `SECURITY_INDIRECT_PROMPT_INJECTION_BASE64_SEQUENTIAL_JAILBREAKING`
* `SECURITY_INDIRECT_PROMPT_INJECTION_BASE64_TREE_JAILBREAKING`
* `SECURITY_JAILBREAK_BASE64`
* `SECURITY_JAILBREAK_BASE64_BAD_LIKERT_JUDGE`
* `SECURITY_JAILBREAK_BASE64_CRESCENDO_JAILBREAKING`
* `SECURITY_JAILBREAK_BASE64_LINEAR_JAILBREAKING`
* `SECURITY_JAILBREAK_BASE64_SEQUENTIAL_JAILBREAKING`
* `SECURITY_JAILBREAK_BASE64_TREE_JAILBREAKING`
* `SECURITY_PROMPT_INJECTION_BASE64`
* `SECURITY_PROMPT_INJECTION_BASE64_BAD_LIKERT_JUDGE`
* `SECURITY_PROMPT_INJECTION_BASE64_CRESCENDO_JAILBREAKING`
* `SECURITY_PROMPT_INJECTION_BASE64_LINEAR_JAILBREAKING`
* `SECURITY_PROMPT_INJECTION_BASE64_SEQUENTIAL_JAILBREAKING`
* `SECURITY_PROMPT_INJECTION_BASE64_TREE_JAILBREAKING`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_BASE64`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_BASE64_BAD_LIKERT_JUDGE`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_BASE64_CRESCENDO_JAILBREAKING`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_BASE64_LINEAR_JAILBREAKING`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_BASE64_SEQUENTIAL_JAILBREAKING`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_BASE64_TREE_JAILBREAKING`

#### Context Poisoning

* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_CONTEXT_POISONING`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_CONTEXT_POISONING_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_CONTEXT_POISONING_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_CONTEXT_POISONING_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_CONTEXT_POISONING_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_CONTEXT_POISONING_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_CONTEXT_POISONING`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_CONTEXT_POISONING_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_CONTEXT_POISONING_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_CONTEXT_POISONING_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_CONTEXT_POISONING_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_CONTEXT_POISONING_TREE_JAILBREAKING`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_CONTEXT_POISONING`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_CONTEXT_POISONING_BAD_LIKERT_JUDGE`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_CONTEXT_POISONING_CRESCENDO_JAILBREAKING`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_CONTEXT_POISONING_LINEAR_JAILBREAKING`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_CONTEXT_POISONING_SEQUENTIAL_JAILBREAKING`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_CONTEXT_POISONING_TREE_JAILBREAKING`
* `SECURITY_INDIRECT_PROMPT_INJECTION_CONTEXT_POISONING`
* `SECURITY_INDIRECT_PROMPT_INJECTION_CONTEXT_POISONING_BAD_LIKERT_JUDGE`
* `SECURITY_INDIRECT_PROMPT_INJECTION_CONTEXT_POISONING_CRESCENDO_JAILBREAKING`
* `SECURITY_INDIRECT_PROMPT_INJECTION_CONTEXT_POISONING_LINEAR_JAILBREAKING`
* `SECURITY_INDIRECT_PROMPT_INJECTION_CONTEXT_POISONING_SEQUENTIAL_JAILBREAKING`
* `SECURITY_INDIRECT_PROMPT_INJECTION_CONTEXT_POISONING_TREE_JAILBREAKING`
* `SECURITY_JAILBREAK_CONTEXT_POISONING`
* `SECURITY_JAILBREAK_CONTEXT_POISONING_BAD_LIKERT_JUDGE`
* `SECURITY_JAILBREAK_CONTEXT_POISONING_CRESCENDO_JAILBREAKING`
* `SECURITY_JAILBREAK_CONTEXT_POISONING_LINEAR_JAILBREAKING`
* `SECURITY_JAILBREAK_CONTEXT_POISONING_SEQUENTIAL_JAILBREAKING`
* `SECURITY_JAILBREAK_CONTEXT_POISONING_TREE_JAILBREAKING`
* `SECURITY_PROMPT_INJECTION_CONTEXT_POISONING`
* `SECURITY_PROMPT_INJECTION_CONTEXT_POISONING_BAD_LIKERT_JUDGE`
* `SECURITY_PROMPT_INJECTION_CONTEXT_POISONING_CRESCENDO_JAILBREAKING`
* `SECURITY_PROMPT_INJECTION_CONTEXT_POISONING_LINEAR_JAILBREAKING`
* `SECURITY_PROMPT_INJECTION_CONTEXT_POISONING_SEQUENTIAL_JAILBREAKING`
* `SECURITY_PROMPT_INJECTION_CONTEXT_POISONING_TREE_JAILBREAKING`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_CONTEXT_POISONING`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_CONTEXT_POISONING_BAD_LIKERT_JUDGE`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_CONTEXT_POISONING_CRESCENDO_JAILBREAKING`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_CONTEXT_POISONING_LINEAR_JAILBREAKING`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_CONTEXT_POISONING_SEQUENTIAL_JAILBREAKING`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_CONTEXT_POISONING_TREE_JAILBREAKING`

#### Goal Redirection

* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_GOAL_REDIRECTION`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_GOAL_REDIRECTION_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_GOAL_REDIRECTION_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_GOAL_REDIRECTION_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_GOAL_REDIRECTION_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_GOAL_REDIRECTION_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_GOAL_REDIRECTION`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_GOAL_REDIRECTION_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_GOAL_REDIRECTION_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_GOAL_REDIRECTION_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_GOAL_REDIRECTION_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_GOAL_REDIRECTION_TREE_JAILBREAKING`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_GOAL_REDIRECTION`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_GOAL_REDIRECTION_BAD_LIKERT_JUDGE`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_GOAL_REDIRECTION_CRESCENDO_JAILBREAKING`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_GOAL_REDIRECTION_LINEAR_JAILBREAKING`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_GOAL_REDIRECTION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_GOAL_REDIRECTION_TREE_JAILBREAKING`
* `SECURITY_INDIRECT_PROMPT_INJECTION_GOAL_REDIRECTION`
* `SECURITY_INDIRECT_PROMPT_INJECTION_GOAL_REDIRECTION_BAD_LIKERT_JUDGE`
* `SECURITY_INDIRECT_PROMPT_INJECTION_GOAL_REDIRECTION_CRESCENDO_JAILBREAKING`
* `SECURITY_INDIRECT_PROMPT_INJECTION_GOAL_REDIRECTION_LINEAR_JAILBREAKING`
* `SECURITY_INDIRECT_PROMPT_INJECTION_GOAL_REDIRECTION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_INDIRECT_PROMPT_INJECTION_GOAL_REDIRECTION_TREE_JAILBREAKING`
* `SECURITY_JAILBREAK_GOAL_REDIRECTION`
* `SECURITY_JAILBREAK_GOAL_REDIRECTION_BAD_LIKERT_JUDGE`
* `SECURITY_JAILBREAK_GOAL_REDIRECTION_CRESCENDO_JAILBREAKING`
* `SECURITY_JAILBREAK_GOAL_REDIRECTION_LINEAR_JAILBREAKING`
* `SECURITY_JAILBREAK_GOAL_REDIRECTION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_JAILBREAK_GOAL_REDIRECTION_TREE_JAILBREAKING`
* `SECURITY_PROMPT_INJECTION_GOAL_REDIRECTION`
* `SECURITY_PROMPT_INJECTION_GOAL_REDIRECTION_BAD_LIKERT_JUDGE`
* `SECURITY_PROMPT_INJECTION_GOAL_REDIRECTION_CRESCENDO_JAILBREAKING`
* `SECURITY_PROMPT_INJECTION_GOAL_REDIRECTION_LINEAR_JAILBREAKING`
* `SECURITY_PROMPT_INJECTION_GOAL_REDIRECTION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_PROMPT_INJECTION_GOAL_REDIRECTION_TREE_JAILBREAKING`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_GOAL_REDIRECTION`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_GOAL_REDIRECTION_BAD_LIKERT_JUDGE`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_GOAL_REDIRECTION_CRESCENDO_JAILBREAKING`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_GOAL_REDIRECTION_LINEAR_JAILBREAKING`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_GOAL_REDIRECTION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_GOAL_REDIRECTION_TREE_JAILBREAKING`

#### Input Bypass

* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_INPUT_BYPASS`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_INPUT_BYPASS_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_INPUT_BYPASS_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_INPUT_BYPASS_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_INPUT_BYPASS_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_INPUT_BYPASS_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_INPUT_BYPASS`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_INPUT_BYPASS_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_INPUT_BYPASS_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_INPUT_BYPASS_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_INPUT_BYPASS_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_INPUT_BYPASS_TREE_JAILBREAKING`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_INPUT_BYPASS`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_INPUT_BYPASS_BAD_LIKERT_JUDGE`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_INPUT_BYPASS_CRESCENDO_JAILBREAKING`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_INPUT_BYPASS_LINEAR_JAILBREAKING`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_INPUT_BYPASS_SEQUENTIAL_JAILBREAKING`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_INPUT_BYPASS_TREE_JAILBREAKING`
* `SECURITY_INDIRECT_PROMPT_INJECTION_INPUT_BYPASS`
* `SECURITY_INDIRECT_PROMPT_INJECTION_INPUT_BYPASS_BAD_LIKERT_JUDGE`
* `SECURITY_INDIRECT_PROMPT_INJECTION_INPUT_BYPASS_CRESCENDO_JAILBREAKING`
* `SECURITY_INDIRECT_PROMPT_INJECTION_INPUT_BYPASS_LINEAR_JAILBREAKING`
* `SECURITY_INDIRECT_PROMPT_INJECTION_INPUT_BYPASS_SEQUENTIAL_JAILBREAKING`
* `SECURITY_INDIRECT_PROMPT_INJECTION_INPUT_BYPASS_TREE_JAILBREAKING`
* `SECURITY_JAILBREAK_INPUT_BYPASS`
* `SECURITY_JAILBREAK_INPUT_BYPASS_BAD_LIKERT_JUDGE`
* `SECURITY_JAILBREAK_INPUT_BYPASS_CRESCENDO_JAILBREAKING`
* `SECURITY_JAILBREAK_INPUT_BYPASS_LINEAR_JAILBREAKING`
* `SECURITY_JAILBREAK_INPUT_BYPASS_SEQUENTIAL_JAILBREAKING`
* `SECURITY_JAILBREAK_INPUT_BYPASS_TREE_JAILBREAKING`
* `SECURITY_PROMPT_INJECTION_INPUT_BYPASS`
* `SECURITY_PROMPT_INJECTION_INPUT_BYPASS_BAD_LIKERT_JUDGE`
* `SECURITY_PROMPT_INJECTION_INPUT_BYPASS_CRESCENDO_JAILBREAKING`
* `SECURITY_PROMPT_INJECTION_INPUT_BYPASS_LINEAR_JAILBREAKING`
* `SECURITY_PROMPT_INJECTION_INPUT_BYPASS_SEQUENTIAL_JAILBREAKING`
* `SECURITY_PROMPT_INJECTION_INPUT_BYPASS_TREE_JAILBREAKING`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_INPUT_BYPASS`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_INPUT_BYPASS_BAD_LIKERT_JUDGE`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_INPUT_BYPASS_CRESCENDO_JAILBREAKING`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_INPUT_BYPASS_LINEAR_JAILBREAKING`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_INPUT_BYPASS_SEQUENTIAL_JAILBREAKING`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_INPUT_BYPASS_TREE_JAILBREAKING`

#### Leetspeak

* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_LEETSPEAK`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_LEETSPEAK_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_LEETSPEAK_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_LEETSPEAK_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_LEETSPEAK_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_LEETSPEAK_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_LEETSPEAK`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_LEETSPEAK_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_LEETSPEAK_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_LEETSPEAK_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_LEETSPEAK_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_LEETSPEAK_TREE_JAILBREAKING`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_LEETSPEAK`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_LEETSPEAK_BAD_LIKERT_JUDGE`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_LEETSPEAK_CRESCENDO_JAILBREAKING`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_LEETSPEAK_LINEAR_JAILBREAKING`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_LEETSPEAK_SEQUENTIAL_JAILBREAKING`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_LEETSPEAK_TREE_JAILBREAKING`
* `SECURITY_INDIRECT_PROMPT_INJECTION_LEETSPEAK`
* `SECURITY_INDIRECT_PROMPT_INJECTION_LEETSPEAK_BAD_LIKERT_JUDGE`
* `SECURITY_INDIRECT_PROMPT_INJECTION_LEETSPEAK_CRESCENDO_JAILBREAKING`
* `SECURITY_INDIRECT_PROMPT_INJECTION_LEETSPEAK_LINEAR_JAILBREAKING`
* `SECURITY_INDIRECT_PROMPT_INJECTION_LEETSPEAK_SEQUENTIAL_JAILBREAKING`
* `SECURITY_INDIRECT_PROMPT_INJECTION_LEETSPEAK_TREE_JAILBREAKING`
* `SECURITY_JAILBREAK_LEETSPEAK`
* `SECURITY_JAILBREAK_LEETSPEAK_BAD_LIKERT_JUDGE`
* `SECURITY_JAILBREAK_LEETSPEAK_CRESCENDO_JAILBREAKING`
* `SECURITY_JAILBREAK_LEETSPEAK_LINEAR_JAILBREAKING`
* `SECURITY_JAILBREAK_LEETSPEAK_SEQUENTIAL_JAILBREAKING`
* `SECURITY_JAILBREAK_LEETSPEAK_TREE_JAILBREAKING`
* `SECURITY_PROMPT_INJECTION_LEETSPEAK`
* `SECURITY_PROMPT_INJECTION_LEETSPEAK_BAD_LIKERT_JUDGE`
* `SECURITY_PROMPT_INJECTION_LEETSPEAK_CRESCENDO_JAILBREAKING`
* `SECURITY_PROMPT_INJECTION_LEETSPEAK_LINEAR_JAILBREAKING`
* `SECURITY_PROMPT_INJECTION_LEETSPEAK_SEQUENTIAL_JAILBREAKING`
* `SECURITY_PROMPT_INJECTION_LEETSPEAK_TREE_JAILBREAKING`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_LEETSPEAK`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_LEETSPEAK_BAD_LIKERT_JUDGE`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_LEETSPEAK_CRESCENDO_JAILBREAKING`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_LEETSPEAK_LINEAR_JAILBREAKING`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_LEETSPEAK_SEQUENTIAL_JAILBREAKING`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_LEETSPEAK_TREE_JAILBREAKING`

#### Math Problem

* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_MATH_PROBLEM`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_MATH_PROBLEM_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_MATH_PROBLEM_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_MATH_PROBLEM_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_MATH_PROBLEM_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_MATH_PROBLEM_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_MATH_PROBLEM`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_MATH_PROBLEM_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_MATH_PROBLEM_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_MATH_PROBLEM_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_MATH_PROBLEM_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_MATH_PROBLEM_TREE_JAILBREAKING`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_MATH_PROBLEM`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_MATH_PROBLEM_BAD_LIKERT_JUDGE`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_MATH_PROBLEM_CRESCENDO_JAILBREAKING`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_MATH_PROBLEM_LINEAR_JAILBREAKING`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_MATH_PROBLEM_SEQUENTIAL_JAILBREAKING`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_MATH_PROBLEM_TREE_JAILBREAKING`
* `SECURITY_INDIRECT_PROMPT_INJECTION_MATH_PROBLEM`
* `SECURITY_INDIRECT_PROMPT_INJECTION_MATH_PROBLEM_BAD_LIKERT_JUDGE`
* `SECURITY_INDIRECT_PROMPT_INJECTION_MATH_PROBLEM_CRESCENDO_JAILBREAKING`
* `SECURITY_INDIRECT_PROMPT_INJECTION_MATH_PROBLEM_LINEAR_JAILBREAKING`
* `SECURITY_INDIRECT_PROMPT_INJECTION_MATH_PROBLEM_SEQUENTIAL_JAILBREAKING`
* `SECURITY_INDIRECT_PROMPT_INJECTION_MATH_PROBLEM_TREE_JAILBREAKING`
* `SECURITY_JAILBREAK_MATH_PROBLEM`
* `SECURITY_JAILBREAK_MATH_PROBLEM_BAD_LIKERT_JUDGE`
* `SECURITY_JAILBREAK_MATH_PROBLEM_CRESCENDO_JAILBREAKING`
* `SECURITY_JAILBREAK_MATH_PROBLEM_LINEAR_JAILBREAKING`
* `SECURITY_JAILBREAK_MATH_PROBLEM_SEQUENTIAL_JAILBREAKING`
* `SECURITY_JAILBREAK_MATH_PROBLEM_TREE_JAILBREAKING`
* `SECURITY_PROMPT_INJECTION_MATH_PROBLEM`
* `SECURITY_PROMPT_INJECTION_MATH_PROBLEM_BAD_LIKERT_JUDGE`
* `SECURITY_PROMPT_INJECTION_MATH_PROBLEM_CRESCENDO_JAILBREAKING`
* `SECURITY_PROMPT_INJECTION_MATH_PROBLEM_LINEAR_JAILBREAKING`
* `SECURITY_PROMPT_INJECTION_MATH_PROBLEM_SEQUENTIAL_JAILBREAKING`
* `SECURITY_PROMPT_INJECTION_MATH_PROBLEM_TREE_JAILBREAKING`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_MATH_PROBLEM`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_MATH_PROBLEM_BAD_LIKERT_JUDGE`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_MATH_PROBLEM_CRESCENDO_JAILBREAKING`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_MATH_PROBLEM_LINEAR_JAILBREAKING`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_MATH_PROBLEM_SEQUENTIAL_JAILBREAKING`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_MATH_PROBLEM_TREE_JAILBREAKING`

#### Multilingual

* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_MULTILINGUAL`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_MULTILINGUAL_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_MULTILINGUAL_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_MULTILINGUAL_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_MULTILINGUAL_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_MULTILINGUAL_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_MULTILINGUAL`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_MULTILINGUAL_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_MULTILINGUAL_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_MULTILINGUAL_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_MULTILINGUAL_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_MULTILINGUAL_TREE_JAILBREAKING`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_MULTILINGUAL`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_MULTILINGUAL_BAD_LIKERT_JUDGE`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_MULTILINGUAL_CRESCENDO_JAILBREAKING`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_MULTILINGUAL_LINEAR_JAILBREAKING`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_MULTILINGUAL_SEQUENTIAL_JAILBREAKING`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_MULTILINGUAL_TREE_JAILBREAKING`
* `SECURITY_INDIRECT_PROMPT_INJECTION_MULTILINGUAL`
* `SECURITY_INDIRECT_PROMPT_INJECTION_MULTILINGUAL_BAD_LIKERT_JUDGE`
* `SECURITY_INDIRECT_PROMPT_INJECTION_MULTILINGUAL_CRESCENDO_JAILBREAKING`
* `SECURITY_INDIRECT_PROMPT_INJECTION_MULTILINGUAL_LINEAR_JAILBREAKING`
* `SECURITY_INDIRECT_PROMPT_INJECTION_MULTILINGUAL_SEQUENTIAL_JAILBREAKING`
* `SECURITY_INDIRECT_PROMPT_INJECTION_MULTILINGUAL_TREE_JAILBREAKING`
* `SECURITY_JAILBREAK_MULTILINGUAL`
* `SECURITY_JAILBREAK_MULTILINGUAL_BAD_LIKERT_JUDGE`
* `SECURITY_JAILBREAK_MULTILINGUAL_CRESCENDO_JAILBREAKING`
* `SECURITY_JAILBREAK_MULTILINGUAL_LINEAR_JAILBREAKING`
* `SECURITY_JAILBREAK_MULTILINGUAL_SEQUENTIAL_JAILBREAKING`
* `SECURITY_JAILBREAK_MULTILINGUAL_TREE_JAILBREAKING`
* `SECURITY_PROMPT_INJECTION_MULTILINGUAL`
* `SECURITY_PROMPT_INJECTION_MULTILINGUAL_BAD_LIKERT_JUDGE`
* `SECURITY_PROMPT_INJECTION_MULTILINGUAL_CRESCENDO_JAILBREAKING`
* `SECURITY_PROMPT_INJECTION_MULTILINGUAL_LINEAR_JAILBREAKING`
* `SECURITY_PROMPT_INJECTION_MULTILINGUAL_SEQUENTIAL_JAILBREAKING`
* `SECURITY_PROMPT_INJECTION_MULTILINGUAL_TREE_JAILBREAKING`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_MULTILINGUAL`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_MULTILINGUAL_BAD_LIKERT_JUDGE`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_MULTILINGUAL_CRESCENDO_JAILBREAKING`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_MULTILINGUAL_LINEAR_JAILBREAKING`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_MULTILINGUAL_SEQUENTIAL_JAILBREAKING`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_MULTILINGUAL_TREE_JAILBREAKING`

#### Permission Escalation

* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_PERMISSION_ESCALATION`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_PERMISSION_ESCALATION_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_PERMISSION_ESCALATION_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_PERMISSION_ESCALATION_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_PERMISSION_ESCALATION_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_PERMISSION_ESCALATION_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_PERMISSION_ESCALATION`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_PERMISSION_ESCALATION_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_PERMISSION_ESCALATION_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_PERMISSION_ESCALATION_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_PERMISSION_ESCALATION_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_PERMISSION_ESCALATION_TREE_JAILBREAKING`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_PERMISSION_ESCALATION`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_PERMISSION_ESCALATION_BAD_LIKERT_JUDGE`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_PERMISSION_ESCALATION_CRESCENDO_JAILBREAKING`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_PERMISSION_ESCALATION_LINEAR_JAILBREAKING`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_PERMISSION_ESCALATION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_PERMISSION_ESCALATION_TREE_JAILBREAKING`
* `SECURITY_INDIRECT_PROMPT_INJECTION_PERMISSION_ESCALATION`
* `SECURITY_INDIRECT_PROMPT_INJECTION_PERMISSION_ESCALATION_BAD_LIKERT_JUDGE`
* `SECURITY_INDIRECT_PROMPT_INJECTION_PERMISSION_ESCALATION_CRESCENDO_JAILBREAKING`
* `SECURITY_INDIRECT_PROMPT_INJECTION_PERMISSION_ESCALATION_LINEAR_JAILBREAKING`
* `SECURITY_INDIRECT_PROMPT_INJECTION_PERMISSION_ESCALATION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_INDIRECT_PROMPT_INJECTION_PERMISSION_ESCALATION_TREE_JAILBREAKING`
* `SECURITY_JAILBREAK_PERMISSION_ESCALATION`
* `SECURITY_JAILBREAK_PERMISSION_ESCALATION_BAD_LIKERT_JUDGE`
* `SECURITY_JAILBREAK_PERMISSION_ESCALATION_CRESCENDO_JAILBREAKING`
* `SECURITY_JAILBREAK_PERMISSION_ESCALATION_LINEAR_JAILBREAKING`
* `SECURITY_JAILBREAK_PERMISSION_ESCALATION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_JAILBREAK_PERMISSION_ESCALATION_TREE_JAILBREAKING`
* `SECURITY_PROMPT_INJECTION_PERMISSION_ESCALATION`
* `SECURITY_PROMPT_INJECTION_PERMISSION_ESCALATION_BAD_LIKERT_JUDGE`
* `SECURITY_PROMPT_INJECTION_PERMISSION_ESCALATION_CRESCENDO_JAILBREAKING`
* `SECURITY_PROMPT_INJECTION_PERMISSION_ESCALATION_LINEAR_JAILBREAKING`
* `SECURITY_PROMPT_INJECTION_PERMISSION_ESCALATION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_PROMPT_INJECTION_PERMISSION_ESCALATION_TREE_JAILBREAKING`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_PERMISSION_ESCALATION`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_PERMISSION_ESCALATION_BAD_LIKERT_JUDGE`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_PERMISSION_ESCALATION_CRESCENDO_JAILBREAKING`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_PERMISSION_ESCALATION_LINEAR_JAILBREAKING`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_PERMISSION_ESCALATION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_PERMISSION_ESCALATION_TREE_JAILBREAKING`

#### Prompt Injection

* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_PROMPT_INJECTION`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_PROMPT_INJECTION_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_PROMPT_INJECTION_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_PROMPT_INJECTION_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_PROMPT_INJECTION_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_PROMPT_INJECTION_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_PROMPT_INJECTION`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_PROMPT_INJECTION_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_PROMPT_INJECTION_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_PROMPT_INJECTION_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_PROMPT_INJECTION_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_PROMPT_INJECTION_TREE_JAILBREAKING`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_PROMPT_INJECTION`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_PROMPT_INJECTION_BAD_LIKERT_JUDGE`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_PROMPT_INJECTION_CRESCENDO_JAILBREAKING`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_PROMPT_INJECTION_LINEAR_JAILBREAKING`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_PROMPT_INJECTION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_PROMPT_INJECTION_TREE_JAILBREAKING`
* `SECURITY_INDIRECT_PROMPT_INJECTION_PROMPT_INJECTION`
* `SECURITY_INDIRECT_PROMPT_INJECTION_PROMPT_INJECTION_BAD_LIKERT_JUDGE`
* `SECURITY_INDIRECT_PROMPT_INJECTION_PROMPT_INJECTION_CRESCENDO_JAILBREAKING`
* `SECURITY_INDIRECT_PROMPT_INJECTION_PROMPT_INJECTION_LINEAR_JAILBREAKING`
* `SECURITY_INDIRECT_PROMPT_INJECTION_PROMPT_INJECTION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_INDIRECT_PROMPT_INJECTION_PROMPT_INJECTION_TREE_JAILBREAKING`
* `SECURITY_JAILBREAK_PROMPT_INJECTION`
* `SECURITY_JAILBREAK_PROMPT_INJECTION_BAD_LIKERT_JUDGE`
* `SECURITY_JAILBREAK_PROMPT_INJECTION_CRESCENDO_JAILBREAKING`
* `SECURITY_JAILBREAK_PROMPT_INJECTION_LINEAR_JAILBREAKING`
* `SECURITY_JAILBREAK_PROMPT_INJECTION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_JAILBREAK_PROMPT_INJECTION_TREE_JAILBREAKING`
* `SECURITY_PROMPT_INJECTION_PROMPT_INJECTION`
* `SECURITY_PROMPT_INJECTION_PROMPT_INJECTION_BAD_LIKERT_JUDGE`
* `SECURITY_PROMPT_INJECTION_PROMPT_INJECTION_CRESCENDO_JAILBREAKING`
* `SECURITY_PROMPT_INJECTION_PROMPT_INJECTION_LINEAR_JAILBREAKING`
* `SECURITY_PROMPT_INJECTION_PROMPT_INJECTION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_PROMPT_INJECTION_PROMPT_INJECTION_TREE_JAILBREAKING`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_PROMPT_INJECTION`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_PROMPT_INJECTION_BAD_LIKERT_JUDGE`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_PROMPT_INJECTION_CRESCENDO_JAILBREAKING`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_PROMPT_INJECTION_LINEAR_JAILBREAKING`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_PROMPT_INJECTION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_PROMPT_INJECTION_TREE_JAILBREAKING`

#### ROT13

* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_ROT13`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_ROT13_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_ROT13_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_ROT13_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_ROT13_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_ROT13_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_ROT13`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_ROT13_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_ROT13_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_ROT13_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_ROT13_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_ROT13_TREE_JAILBREAKING`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_ROT13`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_ROT13_BAD_LIKERT_JUDGE`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_ROT13_CRESCENDO_JAILBREAKING`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_ROT13_LINEAR_JAILBREAKING`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_ROT13_SEQUENTIAL_JAILBREAKING`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_ROT13_TREE_JAILBREAKING`
* `SECURITY_INDIRECT_PROMPT_INJECTION_ROT13`
* `SECURITY_INDIRECT_PROMPT_INJECTION_ROT13_BAD_LIKERT_JUDGE`
* `SECURITY_INDIRECT_PROMPT_INJECTION_ROT13_CRESCENDO_JAILBREAKING`
* `SECURITY_INDIRECT_PROMPT_INJECTION_ROT13_LINEAR_JAILBREAKING`
* `SECURITY_INDIRECT_PROMPT_INJECTION_ROT13_SEQUENTIAL_JAILBREAKING`
* `SECURITY_INDIRECT_PROMPT_INJECTION_ROT13_TREE_JAILBREAKING`
* `SECURITY_JAILBREAK_ROT13`
* `SECURITY_JAILBREAK_ROT13_BAD_LIKERT_JUDGE`
* `SECURITY_JAILBREAK_ROT13_CRESCENDO_JAILBREAKING`
* `SECURITY_JAILBREAK_ROT13_LINEAR_JAILBREAKING`
* `SECURITY_JAILBREAK_ROT13_SEQUENTIAL_JAILBREAKING`
* `SECURITY_JAILBREAK_ROT13_TREE_JAILBREAKING`
* `SECURITY_PROMPT_INJECTION_ROT13`
* `SECURITY_PROMPT_INJECTION_ROT13_BAD_LIKERT_JUDGE`
* `SECURITY_PROMPT_INJECTION_ROT13_CRESCENDO_JAILBREAKING`
* `SECURITY_PROMPT_INJECTION_ROT13_LINEAR_JAILBREAKING`
* `SECURITY_PROMPT_INJECTION_ROT13_SEQUENTIAL_JAILBREAKING`
* `SECURITY_PROMPT_INJECTION_ROT13_TREE_JAILBREAKING`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_ROT13`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_ROT13_BAD_LIKERT_JUDGE`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_ROT13_CRESCENDO_JAILBREAKING`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_ROT13_LINEAR_JAILBREAKING`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_ROT13_SEQUENTIAL_JAILBREAKING`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_ROT13_TREE_JAILBREAKING`

#### Roleplay

* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_ROLEPLAY`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_ROLEPLAY_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_ROLEPLAY_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_ROLEPLAY_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_ROLEPLAY_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_ROLEPLAY_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_ROLEPLAY`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_ROLEPLAY_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_ROLEPLAY_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_ROLEPLAY_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_ROLEPLAY_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_ROLEPLAY_TREE_JAILBREAKING`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_ROLEPLAY`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_ROLEPLAY_BAD_LIKERT_JUDGE`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_ROLEPLAY_CRESCENDO_JAILBREAKING`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_ROLEPLAY_LINEAR_JAILBREAKING`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_ROLEPLAY_SEQUENTIAL_JAILBREAKING`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_ROLEPLAY_TREE_JAILBREAKING`
* `SECURITY_INDIRECT_PROMPT_INJECTION_ROLEPLAY`
* `SECURITY_INDIRECT_PROMPT_INJECTION_ROLEPLAY_BAD_LIKERT_JUDGE`
* `SECURITY_INDIRECT_PROMPT_INJECTION_ROLEPLAY_CRESCENDO_JAILBREAKING`
* `SECURITY_INDIRECT_PROMPT_INJECTION_ROLEPLAY_LINEAR_JAILBREAKING`
* `SECURITY_INDIRECT_PROMPT_INJECTION_ROLEPLAY_SEQUENTIAL_JAILBREAKING`
* `SECURITY_INDIRECT_PROMPT_INJECTION_ROLEPLAY_TREE_JAILBREAKING`
* `SECURITY_JAILBREAK_ROLEPLAY`
* `SECURITY_JAILBREAK_ROLEPLAY_BAD_LIKERT_JUDGE`
* `SECURITY_JAILBREAK_ROLEPLAY_CRESCENDO_JAILBREAKING`
* `SECURITY_JAILBREAK_ROLEPLAY_LINEAR_JAILBREAKING`
* `SECURITY_JAILBREAK_ROLEPLAY_SEQUENTIAL_JAILBREAKING`
* `SECURITY_JAILBREAK_ROLEPLAY_TREE_JAILBREAKING`
* `SECURITY_PROMPT_INJECTION_ROLEPLAY`
* `SECURITY_PROMPT_INJECTION_ROLEPLAY_BAD_LIKERT_JUDGE`
* `SECURITY_PROMPT_INJECTION_ROLEPLAY_CRESCENDO_JAILBREAKING`
* `SECURITY_PROMPT_INJECTION_ROLEPLAY_LINEAR_JAILBREAKING`
* `SECURITY_PROMPT_INJECTION_ROLEPLAY_SEQUENTIAL_JAILBREAKING`
* `SECURITY_PROMPT_INJECTION_ROLEPLAY_TREE_JAILBREAKING`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_ROLEPLAY`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_ROLEPLAY_BAD_LIKERT_JUDGE`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_ROLEPLAY_CRESCENDO_JAILBREAKING`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_ROLEPLAY_LINEAR_JAILBREAKING`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_ROLEPLAY_SEQUENTIAL_JAILBREAKING`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_ROLEPLAY_TREE_JAILBREAKING`

#### Semantic Manipulation

* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_SEMANTIC_MANIPULATION`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_SEMANTIC_MANIPULATION_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_SEMANTIC_MANIPULATION_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_SEMANTIC_MANIPULATION_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_SEMANTIC_MANIPULATION_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_SEMANTIC_MANIPULATION_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_SEMANTIC_MANIPULATION`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_SEMANTIC_MANIPULATION_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_SEMANTIC_MANIPULATION_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_SEMANTIC_MANIPULATION_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_SEMANTIC_MANIPULATION_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_SEMANTIC_MANIPULATION_TREE_JAILBREAKING`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_SEMANTIC_MANIPULATION`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_SEMANTIC_MANIPULATION_BAD_LIKERT_JUDGE`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_SEMANTIC_MANIPULATION_CRESCENDO_JAILBREAKING`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_SEMANTIC_MANIPULATION_LINEAR_JAILBREAKING`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_SEMANTIC_MANIPULATION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_SEMANTIC_MANIPULATION_TREE_JAILBREAKING`
* `SECURITY_INDIRECT_PROMPT_INJECTION_SEMANTIC_MANIPULATION`
* `SECURITY_INDIRECT_PROMPT_INJECTION_SEMANTIC_MANIPULATION_BAD_LIKERT_JUDGE`
* `SECURITY_INDIRECT_PROMPT_INJECTION_SEMANTIC_MANIPULATION_CRESCENDO_JAILBREAKING`
* `SECURITY_INDIRECT_PROMPT_INJECTION_SEMANTIC_MANIPULATION_LINEAR_JAILBREAKING`
* `SECURITY_INDIRECT_PROMPT_INJECTION_SEMANTIC_MANIPULATION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_INDIRECT_PROMPT_INJECTION_SEMANTIC_MANIPULATION_TREE_JAILBREAKING`
* `SECURITY_JAILBREAK_SEMANTIC_MANIPULATION`
* `SECURITY_JAILBREAK_SEMANTIC_MANIPULATION_BAD_LIKERT_JUDGE`
* `SECURITY_JAILBREAK_SEMANTIC_MANIPULATION_CRESCENDO_JAILBREAKING`
* `SECURITY_JAILBREAK_SEMANTIC_MANIPULATION_LINEAR_JAILBREAKING`
* `SECURITY_JAILBREAK_SEMANTIC_MANIPULATION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_JAILBREAK_SEMANTIC_MANIPULATION_TREE_JAILBREAKING`
* `SECURITY_PROMPT_INJECTION_SEMANTIC_MANIPULATION`
* `SECURITY_PROMPT_INJECTION_SEMANTIC_MANIPULATION_BAD_LIKERT_JUDGE`
* `SECURITY_PROMPT_INJECTION_SEMANTIC_MANIPULATION_CRESCENDO_JAILBREAKING`
* `SECURITY_PROMPT_INJECTION_SEMANTIC_MANIPULATION_LINEAR_JAILBREAKING`
* `SECURITY_PROMPT_INJECTION_SEMANTIC_MANIPULATION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_PROMPT_INJECTION_SEMANTIC_MANIPULATION_TREE_JAILBREAKING`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_SEMANTIC_MANIPULATION`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_SEMANTIC_MANIPULATION_BAD_LIKERT_JUDGE`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_SEMANTIC_MANIPULATION_CRESCENDO_JAILBREAKING`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_SEMANTIC_MANIPULATION_LINEAR_JAILBREAKING`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_SEMANTIC_MANIPULATION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_SEMANTIC_MANIPULATION_TREE_JAILBREAKING`

#### System Override

* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_SYSTEM_OVERRIDE`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_SYSTEM_OVERRIDE_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_SYSTEM_OVERRIDE_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_SYSTEM_OVERRIDE_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_SYSTEM_OVERRIDE_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_COMPETITOR_CHECK_SYSTEM_OVERRIDE_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_SYSTEM_OVERRIDE`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_SYSTEM_OVERRIDE_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_SYSTEM_OVERRIDE_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_SYSTEM_OVERRIDE_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_SYSTEM_OVERRIDE_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_INTENTIONAL_MISUSE_SYSTEM_OVERRIDE_TREE_JAILBREAKING`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_SYSTEM_OVERRIDE`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_SYSTEM_OVERRIDE_BAD_LIKERT_JUDGE`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_SYSTEM_OVERRIDE_CRESCENDO_JAILBREAKING`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_SYSTEM_OVERRIDE_LINEAR_JAILBREAKING`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_SYSTEM_OVERRIDE_SEQUENTIAL_JAILBREAKING`
* `SECURITY_AGENT_BEHAVIOR_HIJACK_AND_GOAL_MANIPULATION_SYSTEM_OVERRIDE_TREE_JAILBREAKING`
* `SECURITY_INDIRECT_PROMPT_INJECTION_SYSTEM_OVERRIDE`
* `SECURITY_INDIRECT_PROMPT_INJECTION_SYSTEM_OVERRIDE_BAD_LIKERT_JUDGE`
* `SECURITY_INDIRECT_PROMPT_INJECTION_SYSTEM_OVERRIDE_CRESCENDO_JAILBREAKING`
* `SECURITY_INDIRECT_PROMPT_INJECTION_SYSTEM_OVERRIDE_LINEAR_JAILBREAKING`
* `SECURITY_INDIRECT_PROMPT_INJECTION_SYSTEM_OVERRIDE_SEQUENTIAL_JAILBREAKING`
* `SECURITY_INDIRECT_PROMPT_INJECTION_SYSTEM_OVERRIDE_TREE_JAILBREAKING`
* `SECURITY_JAILBREAK_SYSTEM_OVERRIDE`
* `SECURITY_JAILBREAK_SYSTEM_OVERRIDE_BAD_LIKERT_JUDGE`
* `SECURITY_JAILBREAK_SYSTEM_OVERRIDE_CRESCENDO_JAILBREAKING`
* `SECURITY_JAILBREAK_SYSTEM_OVERRIDE_LINEAR_JAILBREAKING`
* `SECURITY_JAILBREAK_SYSTEM_OVERRIDE_SEQUENTIAL_JAILBREAKING`
* `SECURITY_JAILBREAK_SYSTEM_OVERRIDE_TREE_JAILBREAKING`
* `SECURITY_PROMPT_INJECTION_SYSTEM_OVERRIDE`
* `SECURITY_PROMPT_INJECTION_SYSTEM_OVERRIDE_BAD_LIKERT_JUDGE`
* `SECURITY_PROMPT_INJECTION_SYSTEM_OVERRIDE_CRESCENDO_JAILBREAKING`
* `SECURITY_PROMPT_INJECTION_SYSTEM_OVERRIDE_LINEAR_JAILBREAKING`
* `SECURITY_PROMPT_INJECTION_SYSTEM_OVERRIDE_SEQUENTIAL_JAILBREAKING`
* `SECURITY_PROMPT_INJECTION_SYSTEM_OVERRIDE_TREE_JAILBREAKING`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_SYSTEM_OVERRIDE`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_SYSTEM_OVERRIDE_BAD_LIKERT_JUDGE`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_SYSTEM_OVERRIDE_CRESCENDO_JAILBREAKING`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_SYSTEM_OVERRIDE_LINEAR_JAILBREAKING`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_SYSTEM_OVERRIDE_SEQUENTIAL_JAILBREAKING`
* `SECURITY_SYSTEM_PROMPT_OVERRIDE_SYSTEM_OVERRIDE_TREE_JAILBREAKING`

***

### ASI02: Tool Misuse and Exploitation

#### Base64

* `SECURITY_INSECURE_PLUGIN_USE_BASE64`
* `SECURITY_INSECURE_PLUGIN_USE_BASE64_BAD_LIKERT_JUDGE`
* `SECURITY_INSECURE_PLUGIN_USE_BASE64_CRESCENDO_JAILBREAKING`
* `SECURITY_INSECURE_PLUGIN_USE_BASE64_LINEAR_JAILBREAKING`
* `SECURITY_INSECURE_PLUGIN_USE_BASE64_SEQUENTIAL_JAILBREAKING`
* `SECURITY_INSECURE_PLUGIN_USE_BASE64_TREE_JAILBREAKING`
* `SECURITY_TOOL_DISCOVERY_BASE64`
* `SECURITY_TOOL_DISCOVERY_BASE64_BAD_LIKERT_JUDGE`
* `SECURITY_TOOL_DISCOVERY_BASE64_CRESCENDO_JAILBREAKING`
* `SECURITY_TOOL_DISCOVERY_BASE64_LINEAR_JAILBREAKING`
* `SECURITY_TOOL_DISCOVERY_BASE64_SEQUENTIAL_JAILBREAKING`
* `SECURITY_TOOL_DISCOVERY_BASE64_TREE_JAILBREAKING`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_BASE64`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_BASE64_BAD_LIKERT_JUDGE`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_BASE64_CRESCENDO_JAILBREAKING`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_BASE64_LINEAR_JAILBREAKING`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_BASE64_SEQUENTIAL_JAILBREAKING`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_BASE64_TREE_JAILBREAKING`

#### Context Poisoning

* `SECURITY_INSECURE_PLUGIN_USE_CONTEXT_POISONING`
* `SECURITY_INSECURE_PLUGIN_USE_CONTEXT_POISONING_BAD_LIKERT_JUDGE`
* `SECURITY_INSECURE_PLUGIN_USE_CONTEXT_POISONING_CRESCENDO_JAILBREAKING`
* `SECURITY_INSECURE_PLUGIN_USE_CONTEXT_POISONING_LINEAR_JAILBREAKING`
* `SECURITY_INSECURE_PLUGIN_USE_CONTEXT_POISONING_SEQUENTIAL_JAILBREAKING`
* `SECURITY_INSECURE_PLUGIN_USE_CONTEXT_POISONING_TREE_JAILBREAKING`
* `SECURITY_TOOL_DISCOVERY_CONTEXT_POISONING`
* `SECURITY_TOOL_DISCOVERY_CONTEXT_POISONING_BAD_LIKERT_JUDGE`
* `SECURITY_TOOL_DISCOVERY_CONTEXT_POISONING_CRESCENDO_JAILBREAKING`
* `SECURITY_TOOL_DISCOVERY_CONTEXT_POISONING_LINEAR_JAILBREAKING`
* `SECURITY_TOOL_DISCOVERY_CONTEXT_POISONING_SEQUENTIAL_JAILBREAKING`
* `SECURITY_TOOL_DISCOVERY_CONTEXT_POISONING_TREE_JAILBREAKING`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_CONTEXT_POISONING`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_CONTEXT_POISONING_BAD_LIKERT_JUDGE`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_CONTEXT_POISONING_CRESCENDO_JAILBREAKING`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_CONTEXT_POISONING_LINEAR_JAILBREAKING`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_CONTEXT_POISONING_SEQUENTIAL_JAILBREAKING`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_CONTEXT_POISONING_TREE_JAILBREAKING`

#### Goal Redirection

* `SECURITY_INSECURE_PLUGIN_USE_GOAL_REDIRECTION`
* `SECURITY_INSECURE_PLUGIN_USE_GOAL_REDIRECTION_BAD_LIKERT_JUDGE`
* `SECURITY_INSECURE_PLUGIN_USE_GOAL_REDIRECTION_CRESCENDO_JAILBREAKING`
* `SECURITY_INSECURE_PLUGIN_USE_GOAL_REDIRECTION_LINEAR_JAILBREAKING`
* `SECURITY_INSECURE_PLUGIN_USE_GOAL_REDIRECTION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_INSECURE_PLUGIN_USE_GOAL_REDIRECTION_TREE_JAILBREAKING`
* `SECURITY_TOOL_DISCOVERY_GOAL_REDIRECTION`
* `SECURITY_TOOL_DISCOVERY_GOAL_REDIRECTION_BAD_LIKERT_JUDGE`
* `SECURITY_TOOL_DISCOVERY_GOAL_REDIRECTION_CRESCENDO_JAILBREAKING`
* `SECURITY_TOOL_DISCOVERY_GOAL_REDIRECTION_LINEAR_JAILBREAKING`
* `SECURITY_TOOL_DISCOVERY_GOAL_REDIRECTION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_TOOL_DISCOVERY_GOAL_REDIRECTION_TREE_JAILBREAKING`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_GOAL_REDIRECTION`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_GOAL_REDIRECTION_BAD_LIKERT_JUDGE`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_GOAL_REDIRECTION_CRESCENDO_JAILBREAKING`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_GOAL_REDIRECTION_LINEAR_JAILBREAKING`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_GOAL_REDIRECTION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_GOAL_REDIRECTION_TREE_JAILBREAKING`

#### Input Bypass

* `SECURITY_INSECURE_PLUGIN_USE_INPUT_BYPASS`
* `SECURITY_INSECURE_PLUGIN_USE_INPUT_BYPASS_BAD_LIKERT_JUDGE`
* `SECURITY_INSECURE_PLUGIN_USE_INPUT_BYPASS_CRESCENDO_JAILBREAKING`
* `SECURITY_INSECURE_PLUGIN_USE_INPUT_BYPASS_LINEAR_JAILBREAKING`
* `SECURITY_INSECURE_PLUGIN_USE_INPUT_BYPASS_SEQUENTIAL_JAILBREAKING`
* `SECURITY_INSECURE_PLUGIN_USE_INPUT_BYPASS_TREE_JAILBREAKING`
* `SECURITY_TOOL_DISCOVERY_INPUT_BYPASS`
* `SECURITY_TOOL_DISCOVERY_INPUT_BYPASS_BAD_LIKERT_JUDGE`
* `SECURITY_TOOL_DISCOVERY_INPUT_BYPASS_CRESCENDO_JAILBREAKING`
* `SECURITY_TOOL_DISCOVERY_INPUT_BYPASS_LINEAR_JAILBREAKING`
* `SECURITY_TOOL_DISCOVERY_INPUT_BYPASS_SEQUENTIAL_JAILBREAKING`
* `SECURITY_TOOL_DISCOVERY_INPUT_BYPASS_TREE_JAILBREAKING`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_INPUT_BYPASS`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_INPUT_BYPASS_BAD_LIKERT_JUDGE`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_INPUT_BYPASS_CRESCENDO_JAILBREAKING`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_INPUT_BYPASS_LINEAR_JAILBREAKING`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_INPUT_BYPASS_SEQUENTIAL_JAILBREAKING`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_INPUT_BYPASS_TREE_JAILBREAKING`

#### Leetspeak

* `SECURITY_INSECURE_PLUGIN_USE_LEETSPEAK`
* `SECURITY_INSECURE_PLUGIN_USE_LEETSPEAK_BAD_LIKERT_JUDGE`
* `SECURITY_INSECURE_PLUGIN_USE_LEETSPEAK_CRESCENDO_JAILBREAKING`
* `SECURITY_INSECURE_PLUGIN_USE_LEETSPEAK_LINEAR_JAILBREAKING`
* `SECURITY_INSECURE_PLUGIN_USE_LEETSPEAK_SEQUENTIAL_JAILBREAKING`
* `SECURITY_INSECURE_PLUGIN_USE_LEETSPEAK_TREE_JAILBREAKING`
* `SECURITY_TOOL_DISCOVERY_LEETSPEAK`
* `SECURITY_TOOL_DISCOVERY_LEETSPEAK_BAD_LIKERT_JUDGE`
* `SECURITY_TOOL_DISCOVERY_LEETSPEAK_CRESCENDO_JAILBREAKING`
* `SECURITY_TOOL_DISCOVERY_LEETSPEAK_LINEAR_JAILBREAKING`
* `SECURITY_TOOL_DISCOVERY_LEETSPEAK_SEQUENTIAL_JAILBREAKING`
* `SECURITY_TOOL_DISCOVERY_LEETSPEAK_TREE_JAILBREAKING`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_LEETSPEAK`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_LEETSPEAK_BAD_LIKERT_JUDGE`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_LEETSPEAK_CRESCENDO_JAILBREAKING`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_LEETSPEAK_LINEAR_JAILBREAKING`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_LEETSPEAK_SEQUENTIAL_JAILBREAKING`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_LEETSPEAK_TREE_JAILBREAKING`

#### Math Problem

* `SECURITY_INSECURE_PLUGIN_USE_MATH_PROBLEM`
* `SECURITY_INSECURE_PLUGIN_USE_MATH_PROBLEM_BAD_LIKERT_JUDGE`
* `SECURITY_INSECURE_PLUGIN_USE_MATH_PROBLEM_CRESCENDO_JAILBREAKING`
* `SECURITY_INSECURE_PLUGIN_USE_MATH_PROBLEM_LINEAR_JAILBREAKING`
* `SECURITY_INSECURE_PLUGIN_USE_MATH_PROBLEM_SEQUENTIAL_JAILBREAKING`
* `SECURITY_INSECURE_PLUGIN_USE_MATH_PROBLEM_TREE_JAILBREAKING`
* `SECURITY_TOOL_DISCOVERY_MATH_PROBLEM`
* `SECURITY_TOOL_DISCOVERY_MATH_PROBLEM_BAD_LIKERT_JUDGE`
* `SECURITY_TOOL_DISCOVERY_MATH_PROBLEM_CRESCENDO_JAILBREAKING`
* `SECURITY_TOOL_DISCOVERY_MATH_PROBLEM_LINEAR_JAILBREAKING`
* `SECURITY_TOOL_DISCOVERY_MATH_PROBLEM_SEQUENTIAL_JAILBREAKING`
* `SECURITY_TOOL_DISCOVERY_MATH_PROBLEM_TREE_JAILBREAKING`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_MATH_PROBLEM`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_MATH_PROBLEM_BAD_LIKERT_JUDGE`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_MATH_PROBLEM_CRESCENDO_JAILBREAKING`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_MATH_PROBLEM_LINEAR_JAILBREAKING`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_MATH_PROBLEM_SEQUENTIAL_JAILBREAKING`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_MATH_PROBLEM_TREE_JAILBREAKING`

#### Multilingual

* `SECURITY_INSECURE_PLUGIN_USE_MULTILINGUAL`
* `SECURITY_INSECURE_PLUGIN_USE_MULTILINGUAL_BAD_LIKERT_JUDGE`
* `SECURITY_INSECURE_PLUGIN_USE_MULTILINGUAL_CRESCENDO_JAILBREAKING`
* `SECURITY_INSECURE_PLUGIN_USE_MULTILINGUAL_LINEAR_JAILBREAKING`
* `SECURITY_INSECURE_PLUGIN_USE_MULTILINGUAL_SEQUENTIAL_JAILBREAKING`
* `SECURITY_INSECURE_PLUGIN_USE_MULTILINGUAL_TREE_JAILBREAKING`
* `SECURITY_TOOL_DISCOVERY_MULTILINGUAL`
* `SECURITY_TOOL_DISCOVERY_MULTILINGUAL_BAD_LIKERT_JUDGE`
* `SECURITY_TOOL_DISCOVERY_MULTILINGUAL_CRESCENDO_JAILBREAKING`
* `SECURITY_TOOL_DISCOVERY_MULTILINGUAL_LINEAR_JAILBREAKING`
* `SECURITY_TOOL_DISCOVERY_MULTILINGUAL_SEQUENTIAL_JAILBREAKING`
* `SECURITY_TOOL_DISCOVERY_MULTILINGUAL_TREE_JAILBREAKING`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_MULTILINGUAL`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_MULTILINGUAL_BAD_LIKERT_JUDGE`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_MULTILINGUAL_CRESCENDO_JAILBREAKING`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_MULTILINGUAL_LINEAR_JAILBREAKING`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_MULTILINGUAL_SEQUENTIAL_JAILBREAKING`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_MULTILINGUAL_TREE_JAILBREAKING`

#### Permission Escalation

* `SECURITY_INSECURE_PLUGIN_USE_PERMISSION_ESCALATION`
* `SECURITY_INSECURE_PLUGIN_USE_PERMISSION_ESCALATION_BAD_LIKERT_JUDGE`
* `SECURITY_INSECURE_PLUGIN_USE_PERMISSION_ESCALATION_CRESCENDO_JAILBREAKING`
* `SECURITY_INSECURE_PLUGIN_USE_PERMISSION_ESCALATION_LINEAR_JAILBREAKING`
* `SECURITY_INSECURE_PLUGIN_USE_PERMISSION_ESCALATION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_INSECURE_PLUGIN_USE_PERMISSION_ESCALATION_TREE_JAILBREAKING`
* `SECURITY_TOOL_DISCOVERY_PERMISSION_ESCALATION`
* `SECURITY_TOOL_DISCOVERY_PERMISSION_ESCALATION_BAD_LIKERT_JUDGE`
* `SECURITY_TOOL_DISCOVERY_PERMISSION_ESCALATION_CRESCENDO_JAILBREAKING`
* `SECURITY_TOOL_DISCOVERY_PERMISSION_ESCALATION_LINEAR_JAILBREAKING`
* `SECURITY_TOOL_DISCOVERY_PERMISSION_ESCALATION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_TOOL_DISCOVERY_PERMISSION_ESCALATION_TREE_JAILBREAKING`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_PERMISSION_ESCALATION`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_PERMISSION_ESCALATION_BAD_LIKERT_JUDGE`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_PERMISSION_ESCALATION_CRESCENDO_JAILBREAKING`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_PERMISSION_ESCALATION_LINEAR_JAILBREAKING`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_PERMISSION_ESCALATION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_PERMISSION_ESCALATION_TREE_JAILBREAKING`

#### Prompt Injection

* `SECURITY_INSECURE_PLUGIN_USE_PROMPT_INJECTION`
* `SECURITY_INSECURE_PLUGIN_USE_PROMPT_INJECTION_BAD_LIKERT_JUDGE`
* `SECURITY_INSECURE_PLUGIN_USE_PROMPT_INJECTION_CRESCENDO_JAILBREAKING`
* `SECURITY_INSECURE_PLUGIN_USE_PROMPT_INJECTION_LINEAR_JAILBREAKING`
* `SECURITY_INSECURE_PLUGIN_USE_PROMPT_INJECTION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_INSECURE_PLUGIN_USE_PROMPT_INJECTION_TREE_JAILBREAKING`
* `SECURITY_TOOL_DISCOVERY_PROMPT_INJECTION`
* `SECURITY_TOOL_DISCOVERY_PROMPT_INJECTION_BAD_LIKERT_JUDGE`
* `SECURITY_TOOL_DISCOVERY_PROMPT_INJECTION_CRESCENDO_JAILBREAKING`
* `SECURITY_TOOL_DISCOVERY_PROMPT_INJECTION_LINEAR_JAILBREAKING`
* `SECURITY_TOOL_DISCOVERY_PROMPT_INJECTION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_TOOL_DISCOVERY_PROMPT_INJECTION_TREE_JAILBREAKING`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_PROMPT_INJECTION`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_PROMPT_INJECTION_BAD_LIKERT_JUDGE`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_PROMPT_INJECTION_CRESCENDO_JAILBREAKING`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_PROMPT_INJECTION_LINEAR_JAILBREAKING`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_PROMPT_INJECTION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_PROMPT_INJECTION_TREE_JAILBREAKING`

#### ROT13

* `SECURITY_INSECURE_PLUGIN_USE_ROT13`
* `SECURITY_INSECURE_PLUGIN_USE_ROT13_BAD_LIKERT_JUDGE`
* `SECURITY_INSECURE_PLUGIN_USE_ROT13_CRESCENDO_JAILBREAKING`
* `SECURITY_INSECURE_PLUGIN_USE_ROT13_LINEAR_JAILBREAKING`
* `SECURITY_INSECURE_PLUGIN_USE_ROT13_SEQUENTIAL_JAILBREAKING`
* `SECURITY_INSECURE_PLUGIN_USE_ROT13_TREE_JAILBREAKING`
* `SECURITY_TOOL_DISCOVERY_ROT13`
* `SECURITY_TOOL_DISCOVERY_ROT13_BAD_LIKERT_JUDGE`
* `SECURITY_TOOL_DISCOVERY_ROT13_CRESCENDO_JAILBREAKING`
* `SECURITY_TOOL_DISCOVERY_ROT13_LINEAR_JAILBREAKING`
* `SECURITY_TOOL_DISCOVERY_ROT13_SEQUENTIAL_JAILBREAKING`
* `SECURITY_TOOL_DISCOVERY_ROT13_TREE_JAILBREAKING`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_ROT13`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_ROT13_BAD_LIKERT_JUDGE`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_ROT13_CRESCENDO_JAILBREAKING`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_ROT13_LINEAR_JAILBREAKING`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_ROT13_SEQUENTIAL_JAILBREAKING`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_ROT13_TREE_JAILBREAKING`

#### Roleplay

* `SECURITY_INSECURE_PLUGIN_USE_ROLEPLAY`
* `SECURITY_INSECURE_PLUGIN_USE_ROLEPLAY_BAD_LIKERT_JUDGE`
* `SECURITY_INSECURE_PLUGIN_USE_ROLEPLAY_CRESCENDO_JAILBREAKING`
* `SECURITY_INSECURE_PLUGIN_USE_ROLEPLAY_LINEAR_JAILBREAKING`
* `SECURITY_INSECURE_PLUGIN_USE_ROLEPLAY_SEQUENTIAL_JAILBREAKING`
* `SECURITY_INSECURE_PLUGIN_USE_ROLEPLAY_TREE_JAILBREAKING`
* `SECURITY_TOOL_DISCOVERY_ROLEPLAY`
* `SECURITY_TOOL_DISCOVERY_ROLEPLAY_BAD_LIKERT_JUDGE`
* `SECURITY_TOOL_DISCOVERY_ROLEPLAY_CRESCENDO_JAILBREAKING`
* `SECURITY_TOOL_DISCOVERY_ROLEPLAY_LINEAR_JAILBREAKING`
* `SECURITY_TOOL_DISCOVERY_ROLEPLAY_SEQUENTIAL_JAILBREAKING`
* `SECURITY_TOOL_DISCOVERY_ROLEPLAY_TREE_JAILBREAKING`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_ROLEPLAY`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_ROLEPLAY_BAD_LIKERT_JUDGE`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_ROLEPLAY_CRESCENDO_JAILBREAKING`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_ROLEPLAY_LINEAR_JAILBREAKING`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_ROLEPLAY_SEQUENTIAL_JAILBREAKING`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_ROLEPLAY_TREE_JAILBREAKING`

#### Semantic Manipulation

* `SECURITY_INSECURE_PLUGIN_USE_SEMANTIC_MANIPULATION`
* `SECURITY_INSECURE_PLUGIN_USE_SEMANTIC_MANIPULATION_BAD_LIKERT_JUDGE`
* `SECURITY_INSECURE_PLUGIN_USE_SEMANTIC_MANIPULATION_CRESCENDO_JAILBREAKING`
* `SECURITY_INSECURE_PLUGIN_USE_SEMANTIC_MANIPULATION_LINEAR_JAILBREAKING`
* `SECURITY_INSECURE_PLUGIN_USE_SEMANTIC_MANIPULATION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_INSECURE_PLUGIN_USE_SEMANTIC_MANIPULATION_TREE_JAILBREAKING`
* `SECURITY_TOOL_DISCOVERY_SEMANTIC_MANIPULATION`
* `SECURITY_TOOL_DISCOVERY_SEMANTIC_MANIPULATION_BAD_LIKERT_JUDGE`
* `SECURITY_TOOL_DISCOVERY_SEMANTIC_MANIPULATION_CRESCENDO_JAILBREAKING`
* `SECURITY_TOOL_DISCOVERY_SEMANTIC_MANIPULATION_LINEAR_JAILBREAKING`
* `SECURITY_TOOL_DISCOVERY_SEMANTIC_MANIPULATION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_TOOL_DISCOVERY_SEMANTIC_MANIPULATION_TREE_JAILBREAKING`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_SEMANTIC_MANIPULATION`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_SEMANTIC_MANIPULATION_BAD_LIKERT_JUDGE`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_SEMANTIC_MANIPULATION_CRESCENDO_JAILBREAKING`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_SEMANTIC_MANIPULATION_LINEAR_JAILBREAKING`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_SEMANTIC_MANIPULATION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_SEMANTIC_MANIPULATION_TREE_JAILBREAKING`

#### System Override

* `SECURITY_INSECURE_PLUGIN_USE_SYSTEM_OVERRIDE`
* `SECURITY_INSECURE_PLUGIN_USE_SYSTEM_OVERRIDE_BAD_LIKERT_JUDGE`
* `SECURITY_INSECURE_PLUGIN_USE_SYSTEM_OVERRIDE_CRESCENDO_JAILBREAKING`
* `SECURITY_INSECURE_PLUGIN_USE_SYSTEM_OVERRIDE_LINEAR_JAILBREAKING`
* `SECURITY_INSECURE_PLUGIN_USE_SYSTEM_OVERRIDE_SEQUENTIAL_JAILBREAKING`
* `SECURITY_INSECURE_PLUGIN_USE_SYSTEM_OVERRIDE_TREE_JAILBREAKING`
* `SECURITY_TOOL_DISCOVERY_SYSTEM_OVERRIDE`
* `SECURITY_TOOL_DISCOVERY_SYSTEM_OVERRIDE_BAD_LIKERT_JUDGE`
* `SECURITY_TOOL_DISCOVERY_SYSTEM_OVERRIDE_CRESCENDO_JAILBREAKING`
* `SECURITY_TOOL_DISCOVERY_SYSTEM_OVERRIDE_LINEAR_JAILBREAKING`
* `SECURITY_TOOL_DISCOVERY_SYSTEM_OVERRIDE_SEQUENTIAL_JAILBREAKING`
* `SECURITY_TOOL_DISCOVERY_SYSTEM_OVERRIDE_TREE_JAILBREAKING`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_SYSTEM_OVERRIDE`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_SYSTEM_OVERRIDE_BAD_LIKERT_JUDGE`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_SYSTEM_OVERRIDE_CRESCENDO_JAILBREAKING`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_SYSTEM_OVERRIDE_LINEAR_JAILBREAKING`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_SYSTEM_OVERRIDE_SEQUENTIAL_JAILBREAKING`
* `SECURITY_TOOL_MISUSE_AND_EXPLOITATION_SYSTEM_OVERRIDE_TREE_JAILBREAKING`

***

### ASI03: Identity and Privilege Abuse

#### Base64

* `SAFETY_PII_BASE64`
* `SAFETY_PII_BASE64_BAD_LIKERT_JUDGE`
* `SAFETY_PII_BASE64_CRESCENDO_JAILBREAKING`
* `SAFETY_PII_BASE64_LINEAR_JAILBREAKING`
* `SAFETY_PII_BASE64_SEQUENTIAL_JAILBREAKING`
* `SAFETY_PII_BASE64_TREE_JAILBREAKING`
* `SAFETY_PRIVACY_VIOLATION_BASE64`
* `SAFETY_PRIVACY_VIOLATION_BASE64_BAD_LIKERT_JUDGE`
* `SAFETY_PRIVACY_VIOLATION_BASE64_CRESCENDO_JAILBREAKING`
* `SAFETY_PRIVACY_VIOLATION_BASE64_LINEAR_JAILBREAKING`
* `SAFETY_PRIVACY_VIOLATION_BASE64_SEQUENTIAL_JAILBREAKING`
* `SAFETY_PRIVACY_VIOLATION_BASE64_TREE_JAILBREAKING`
* `SECURITY_IDENTITY_SPOOFING_BASE64`
* `SECURITY_IDENTITY_SPOOFING_BASE64_BAD_LIKERT_JUDGE`
* `SECURITY_IDENTITY_SPOOFING_BASE64_CRESCENDO_JAILBREAKING`
* `SECURITY_IDENTITY_SPOOFING_BASE64_LINEAR_JAILBREAKING`
* `SECURITY_IDENTITY_SPOOFING_BASE64_SEQUENTIAL_JAILBREAKING`
* `SECURITY_IDENTITY_SPOOFING_BASE64_TREE_JAILBREAKING`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_BASE64`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_BASE64_BAD_LIKERT_JUDGE`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_BASE64_CRESCENDO_JAILBREAKING`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_BASE64_LINEAR_JAILBREAKING`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_BASE64_SEQUENTIAL_JAILBREAKING`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_BASE64_TREE_JAILBREAKING`

#### Context Poisoning

* `SAFETY_PII_CONTEXT_POISONING`
* `SAFETY_PII_CONTEXT_POISONING_BAD_LIKERT_JUDGE`
* `SAFETY_PII_CONTEXT_POISONING_CRESCENDO_JAILBREAKING`
* `SAFETY_PII_CONTEXT_POISONING_LINEAR_JAILBREAKING`
* `SAFETY_PII_CONTEXT_POISONING_SEQUENTIAL_JAILBREAKING`
* `SAFETY_PII_CONTEXT_POISONING_TREE_JAILBREAKING`
* `SAFETY_PRIVACY_VIOLATION_CONTEXT_POISONING`
* `SAFETY_PRIVACY_VIOLATION_CONTEXT_POISONING_BAD_LIKERT_JUDGE`
* `SAFETY_PRIVACY_VIOLATION_CONTEXT_POISONING_CRESCENDO_JAILBREAKING`
* `SAFETY_PRIVACY_VIOLATION_CONTEXT_POISONING_LINEAR_JAILBREAKING`
* `SAFETY_PRIVACY_VIOLATION_CONTEXT_POISONING_SEQUENTIAL_JAILBREAKING`
* `SAFETY_PRIVACY_VIOLATION_CONTEXT_POISONING_TREE_JAILBREAKING`
* `SECURITY_IDENTITY_SPOOFING_CONTEXT_POISONING`
* `SECURITY_IDENTITY_SPOOFING_CONTEXT_POISONING_BAD_LIKERT_JUDGE`
* `SECURITY_IDENTITY_SPOOFING_CONTEXT_POISONING_CRESCENDO_JAILBREAKING`
* `SECURITY_IDENTITY_SPOOFING_CONTEXT_POISONING_LINEAR_JAILBREAKING`
* `SECURITY_IDENTITY_SPOOFING_CONTEXT_POISONING_SEQUENTIAL_JAILBREAKING`
* `SECURITY_IDENTITY_SPOOFING_CONTEXT_POISONING_TREE_JAILBREAKING`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_CONTEXT_POISONING`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_CONTEXT_POISONING_BAD_LIKERT_JUDGE`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_CONTEXT_POISONING_CRESCENDO_JAILBREAKING`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_CONTEXT_POISONING_LINEAR_JAILBREAKING`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_CONTEXT_POISONING_SEQUENTIAL_JAILBREAKING`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_CONTEXT_POISONING_TREE_JAILBREAKING`

#### Goal Redirection

* `SAFETY_PII_GOAL_REDIRECTION`
* `SAFETY_PII_GOAL_REDIRECTION_BAD_LIKERT_JUDGE`
* `SAFETY_PII_GOAL_REDIRECTION_CRESCENDO_JAILBREAKING`
* `SAFETY_PII_GOAL_REDIRECTION_LINEAR_JAILBREAKING`
* `SAFETY_PII_GOAL_REDIRECTION_SEQUENTIAL_JAILBREAKING`
* `SAFETY_PII_GOAL_REDIRECTION_TREE_JAILBREAKING`
* `SAFETY_PRIVACY_VIOLATION_GOAL_REDIRECTION`
* `SAFETY_PRIVACY_VIOLATION_GOAL_REDIRECTION_BAD_LIKERT_JUDGE`
* `SAFETY_PRIVACY_VIOLATION_GOAL_REDIRECTION_CRESCENDO_JAILBREAKING`
* `SAFETY_PRIVACY_VIOLATION_GOAL_REDIRECTION_LINEAR_JAILBREAKING`
* `SAFETY_PRIVACY_VIOLATION_GOAL_REDIRECTION_SEQUENTIAL_JAILBREAKING`
* `SAFETY_PRIVACY_VIOLATION_GOAL_REDIRECTION_TREE_JAILBREAKING`
* `SECURITY_IDENTITY_SPOOFING_GOAL_REDIRECTION`
* `SECURITY_IDENTITY_SPOOFING_GOAL_REDIRECTION_BAD_LIKERT_JUDGE`
* `SECURITY_IDENTITY_SPOOFING_GOAL_REDIRECTION_CRESCENDO_JAILBREAKING`
* `SECURITY_IDENTITY_SPOOFING_GOAL_REDIRECTION_LINEAR_JAILBREAKING`
* `SECURITY_IDENTITY_SPOOFING_GOAL_REDIRECTION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_IDENTITY_SPOOFING_GOAL_REDIRECTION_TREE_JAILBREAKING`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_GOAL_REDIRECTION`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_GOAL_REDIRECTION_BAD_LIKERT_JUDGE`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_GOAL_REDIRECTION_CRESCENDO_JAILBREAKING`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_GOAL_REDIRECTION_LINEAR_JAILBREAKING`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_GOAL_REDIRECTION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_GOAL_REDIRECTION_TREE_JAILBREAKING`

#### Input Bypass

* `SAFETY_PII_INPUT_BYPASS`
* `SAFETY_PII_INPUT_BYPASS_BAD_LIKERT_JUDGE`
* `SAFETY_PII_INPUT_BYPASS_CRESCENDO_JAILBREAKING`
* `SAFETY_PII_INPUT_BYPASS_LINEAR_JAILBREAKING`
* `SAFETY_PII_INPUT_BYPASS_SEQUENTIAL_JAILBREAKING`
* `SAFETY_PII_INPUT_BYPASS_TREE_JAILBREAKING`
* `SAFETY_PRIVACY_VIOLATION_INPUT_BYPASS`
* `SAFETY_PRIVACY_VIOLATION_INPUT_BYPASS_BAD_LIKERT_JUDGE`
* `SAFETY_PRIVACY_VIOLATION_INPUT_BYPASS_CRESCENDO_JAILBREAKING`
* `SAFETY_PRIVACY_VIOLATION_INPUT_BYPASS_LINEAR_JAILBREAKING`
* `SAFETY_PRIVACY_VIOLATION_INPUT_BYPASS_SEQUENTIAL_JAILBREAKING`
* `SAFETY_PRIVACY_VIOLATION_INPUT_BYPASS_TREE_JAILBREAKING`
* `SECURITY_CROSS_SESSION_LEAKS_INPUT_BYPASS`
* `SECURITY_CROSS_SESSION_LEAKS_INPUT_BYPASS_BAD_LIKERT_JUDGE`
* `SECURITY_CROSS_SESSION_LEAKS_INPUT_BYPASS_CRESCENDO_JAILBREAKING`
* `SECURITY_CROSS_SESSION_LEAKS_INPUT_BYPASS_LINEAR_JAILBREAKING`
* `SECURITY_CROSS_SESSION_LEAKS_INPUT_BYPASS_SEQUENTIAL_JAILBREAKING`
* `SECURITY_CROSS_SESSION_LEAKS_INPUT_BYPASS_TREE_JAILBREAKING`
* `SECURITY_IDENTITY_SPOOFING_INPUT_BYPASS`
* `SECURITY_IDENTITY_SPOOFING_INPUT_BYPASS_BAD_LIKERT_JUDGE`
* `SECURITY_IDENTITY_SPOOFING_INPUT_BYPASS_CRESCENDO_JAILBREAKING`
* `SECURITY_IDENTITY_SPOOFING_INPUT_BYPASS_LINEAR_JAILBREAKING`
* `SECURITY_IDENTITY_SPOOFING_INPUT_BYPASS_SEQUENTIAL_JAILBREAKING`
* `SECURITY_IDENTITY_SPOOFING_INPUT_BYPASS_TREE_JAILBREAKING`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_INPUT_BYPASS`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_INPUT_BYPASS_BAD_LIKERT_JUDGE`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_INPUT_BYPASS_CRESCENDO_JAILBREAKING`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_INPUT_BYPASS_LINEAR_JAILBREAKING`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_INPUT_BYPASS_SEQUENTIAL_JAILBREAKING`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_INPUT_BYPASS_TREE_JAILBREAKING`

#### Leetspeak

* `SAFETY_PII_LEETSPEAK`
* `SAFETY_PII_LEETSPEAK_BAD_LIKERT_JUDGE`
* `SAFETY_PII_LEETSPEAK_CRESCENDO_JAILBREAKING`
* `SAFETY_PII_LEETSPEAK_LINEAR_JAILBREAKING`
* `SAFETY_PII_LEETSPEAK_SEQUENTIAL_JAILBREAKING`
* `SAFETY_PII_LEETSPEAK_TREE_JAILBREAKING`
* `SAFETY_PRIVACY_VIOLATION_LEETSPEAK`
* `SAFETY_PRIVACY_VIOLATION_LEETSPEAK_BAD_LIKERT_JUDGE`
* `SAFETY_PRIVACY_VIOLATION_LEETSPEAK_CRESCENDO_JAILBREAKING`
* `SAFETY_PRIVACY_VIOLATION_LEETSPEAK_LINEAR_JAILBREAKING`
* `SAFETY_PRIVACY_VIOLATION_LEETSPEAK_SEQUENTIAL_JAILBREAKING`
* `SAFETY_PRIVACY_VIOLATION_LEETSPEAK_TREE_JAILBREAKING`
* `SECURITY_IDENTITY_SPOOFING_LEETSPEAK`
* `SECURITY_IDENTITY_SPOOFING_LEETSPEAK_BAD_LIKERT_JUDGE`
* `SECURITY_IDENTITY_SPOOFING_LEETSPEAK_CRESCENDO_JAILBREAKING`
* `SECURITY_IDENTITY_SPOOFING_LEETSPEAK_LINEAR_JAILBREAKING`
* `SECURITY_IDENTITY_SPOOFING_LEETSPEAK_SEQUENTIAL_JAILBREAKING`
* `SECURITY_IDENTITY_SPOOFING_LEETSPEAK_TREE_JAILBREAKING`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_LEETSPEAK`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_LEETSPEAK_BAD_LIKERT_JUDGE`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_LEETSPEAK_CRESCENDO_JAILBREAKING`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_LEETSPEAK_LINEAR_JAILBREAKING`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_LEETSPEAK_SEQUENTIAL_JAILBREAKING`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_LEETSPEAK_TREE_JAILBREAKING`

#### Math Problem

* `SAFETY_PII_MATH_PROBLEM`
* `SAFETY_PII_MATH_PROBLEM_BAD_LIKERT_JUDGE`
* `SAFETY_PII_MATH_PROBLEM_CRESCENDO_JAILBREAKING`
* `SAFETY_PII_MATH_PROBLEM_LINEAR_JAILBREAKING`
* `SAFETY_PII_MATH_PROBLEM_SEQUENTIAL_JAILBREAKING`
* `SAFETY_PII_MATH_PROBLEM_TREE_JAILBREAKING`
* `SAFETY_PRIVACY_VIOLATION_MATH_PROBLEM`
* `SAFETY_PRIVACY_VIOLATION_MATH_PROBLEM_BAD_LIKERT_JUDGE`
* `SAFETY_PRIVACY_VIOLATION_MATH_PROBLEM_CRESCENDO_JAILBREAKING`
* `SAFETY_PRIVACY_VIOLATION_MATH_PROBLEM_LINEAR_JAILBREAKING`
* `SAFETY_PRIVACY_VIOLATION_MATH_PROBLEM_SEQUENTIAL_JAILBREAKING`
* `SAFETY_PRIVACY_VIOLATION_MATH_PROBLEM_TREE_JAILBREAKING`
* `SECURITY_IDENTITY_SPOOFING_MATH_PROBLEM`
* `SECURITY_IDENTITY_SPOOFING_MATH_PROBLEM_BAD_LIKERT_JUDGE`
* `SECURITY_IDENTITY_SPOOFING_MATH_PROBLEM_CRESCENDO_JAILBREAKING`
* `SECURITY_IDENTITY_SPOOFING_MATH_PROBLEM_LINEAR_JAILBREAKING`
* `SECURITY_IDENTITY_SPOOFING_MATH_PROBLEM_SEQUENTIAL_JAILBREAKING`
* `SECURITY_IDENTITY_SPOOFING_MATH_PROBLEM_TREE_JAILBREAKING`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_MATH_PROBLEM`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_MATH_PROBLEM_BAD_LIKERT_JUDGE`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_MATH_PROBLEM_CRESCENDO_JAILBREAKING`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_MATH_PROBLEM_LINEAR_JAILBREAKING`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_MATH_PROBLEM_SEQUENTIAL_JAILBREAKING`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_MATH_PROBLEM_TREE_JAILBREAKING`

#### Multilingual

* `SAFETY_PII_MULTILINGUAL`
* `SAFETY_PII_MULTILINGUAL_BAD_LIKERT_JUDGE`
* `SAFETY_PII_MULTILINGUAL_CRESCENDO_JAILBREAKING`
* `SAFETY_PII_MULTILINGUAL_LINEAR_JAILBREAKING`
* `SAFETY_PII_MULTILINGUAL_SEQUENTIAL_JAILBREAKING`
* `SAFETY_PII_MULTILINGUAL_TREE_JAILBREAKING`
* `SAFETY_PRIVACY_VIOLATION_MULTILINGUAL`
* `SAFETY_PRIVACY_VIOLATION_MULTILINGUAL_BAD_LIKERT_JUDGE`
* `SAFETY_PRIVACY_VIOLATION_MULTILINGUAL_CRESCENDO_JAILBREAKING`
* `SAFETY_PRIVACY_VIOLATION_MULTILINGUAL_LINEAR_JAILBREAKING`
* `SAFETY_PRIVACY_VIOLATION_MULTILINGUAL_SEQUENTIAL_JAILBREAKING`
* `SAFETY_PRIVACY_VIOLATION_MULTILINGUAL_TREE_JAILBREAKING`
* `SECURITY_IDENTITY_SPOOFING_MULTILINGUAL`
* `SECURITY_IDENTITY_SPOOFING_MULTILINGUAL_BAD_LIKERT_JUDGE`
* `SECURITY_IDENTITY_SPOOFING_MULTILINGUAL_CRESCENDO_JAILBREAKING`
* `SECURITY_IDENTITY_SPOOFING_MULTILINGUAL_LINEAR_JAILBREAKING`
* `SECURITY_IDENTITY_SPOOFING_MULTILINGUAL_SEQUENTIAL_JAILBREAKING`
* `SECURITY_IDENTITY_SPOOFING_MULTILINGUAL_TREE_JAILBREAKING`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_MULTILINGUAL`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_MULTILINGUAL_BAD_LIKERT_JUDGE`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_MULTILINGUAL_CRESCENDO_JAILBREAKING`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_MULTILINGUAL_LINEAR_JAILBREAKING`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_MULTILINGUAL_SEQUENTIAL_JAILBREAKING`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_MULTILINGUAL_TREE_JAILBREAKING`

#### Permission Escalation

* `SAFETY_PII_PERMISSION_ESCALATION`
* `SAFETY_PII_PERMISSION_ESCALATION_BAD_LIKERT_JUDGE`
* `SAFETY_PII_PERMISSION_ESCALATION_CRESCENDO_JAILBREAKING`
* `SAFETY_PII_PERMISSION_ESCALATION_LINEAR_JAILBREAKING`
* `SAFETY_PII_PERMISSION_ESCALATION_SEQUENTIAL_JAILBREAKING`
* `SAFETY_PII_PERMISSION_ESCALATION_TREE_JAILBREAKING`
* `SAFETY_PRIVACY_VIOLATION_PERMISSION_ESCALATION`
* `SAFETY_PRIVACY_VIOLATION_PERMISSION_ESCALATION_BAD_LIKERT_JUDGE`
* `SAFETY_PRIVACY_VIOLATION_PERMISSION_ESCALATION_CRESCENDO_JAILBREAKING`
* `SAFETY_PRIVACY_VIOLATION_PERMISSION_ESCALATION_LINEAR_JAILBREAKING`
* `SAFETY_PRIVACY_VIOLATION_PERMISSION_ESCALATION_SEQUENTIAL_JAILBREAKING`
* `SAFETY_PRIVACY_VIOLATION_PERMISSION_ESCALATION_TREE_JAILBREAKING`
* `SECURITY_CROSS_SESSION_LEAKS_PERMISSION_ESCALATION`
* `SECURITY_CROSS_SESSION_LEAKS_PERMISSION_ESCALATION_BAD_LIKERT_JUDGE`
* `SECURITY_CROSS_SESSION_LEAKS_PERMISSION_ESCALATION_CRESCENDO_JAILBREAKING`
* `SECURITY_CROSS_SESSION_LEAKS_PERMISSION_ESCALATION_LINEAR_JAILBREAKING`
* `SECURITY_CROSS_SESSION_LEAKS_PERMISSION_ESCALATION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_CROSS_SESSION_LEAKS_PERMISSION_ESCALATION_TREE_JAILBREAKING`
* `SECURITY_IDENTITY_SPOOFING_PERMISSION_ESCALATION`
* `SECURITY_IDENTITY_SPOOFING_PERMISSION_ESCALATION_BAD_LIKERT_JUDGE`
* `SECURITY_IDENTITY_SPOOFING_PERMISSION_ESCALATION_CRESCENDO_JAILBREAKING`
* `SECURITY_IDENTITY_SPOOFING_PERMISSION_ESCALATION_LINEAR_JAILBREAKING`
* `SECURITY_IDENTITY_SPOOFING_PERMISSION_ESCALATION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_IDENTITY_SPOOFING_PERMISSION_ESCALATION_TREE_JAILBREAKING`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_PERMISSION_ESCALATION`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_PERMISSION_ESCALATION_BAD_LIKERT_JUDGE`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_PERMISSION_ESCALATION_CRESCENDO_JAILBREAKING`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_PERMISSION_ESCALATION_LINEAR_JAILBREAKING`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_PERMISSION_ESCALATION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_PERMISSION_ESCALATION_TREE_JAILBREAKING`

#### Prompt Injection

* `SAFETY_PII_PROMPT_INJECTION`
* `SAFETY_PII_PROMPT_INJECTION_BAD_LIKERT_JUDGE`
* `SAFETY_PII_PROMPT_INJECTION_CRESCENDO_JAILBREAKING`
* `SAFETY_PII_PROMPT_INJECTION_LINEAR_JAILBREAKING`
* `SAFETY_PII_PROMPT_INJECTION_SEQUENTIAL_JAILBREAKING`
* `SAFETY_PII_PROMPT_INJECTION_TREE_JAILBREAKING`
* `SAFETY_PRIVACY_VIOLATION_PROMPT_INJECTION`
* `SAFETY_PRIVACY_VIOLATION_PROMPT_INJECTION_BAD_LIKERT_JUDGE`
* `SAFETY_PRIVACY_VIOLATION_PROMPT_INJECTION_CRESCENDO_JAILBREAKING`
* `SAFETY_PRIVACY_VIOLATION_PROMPT_INJECTION_LINEAR_JAILBREAKING`
* `SAFETY_PRIVACY_VIOLATION_PROMPT_INJECTION_SEQUENTIAL_JAILBREAKING`
* `SAFETY_PRIVACY_VIOLATION_PROMPT_INJECTION_TREE_JAILBREAKING`
* `SECURITY_IDENTITY_SPOOFING_PROMPT_INJECTION`
* `SECURITY_IDENTITY_SPOOFING_PROMPT_INJECTION_BAD_LIKERT_JUDGE`
* `SECURITY_IDENTITY_SPOOFING_PROMPT_INJECTION_CRESCENDO_JAILBREAKING`
* `SECURITY_IDENTITY_SPOOFING_PROMPT_INJECTION_LINEAR_JAILBREAKING`
* `SECURITY_IDENTITY_SPOOFING_PROMPT_INJECTION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_IDENTITY_SPOOFING_PROMPT_INJECTION_TREE_JAILBREAKING`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_PROMPT_INJECTION`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_PROMPT_INJECTION_BAD_LIKERT_JUDGE`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_PROMPT_INJECTION_CRESCENDO_JAILBREAKING`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_PROMPT_INJECTION_LINEAR_JAILBREAKING`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_PROMPT_INJECTION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_PROMPT_INJECTION_TREE_JAILBREAKING`

#### ROT13

* `SAFETY_PII_ROT13`
* `SAFETY_PII_ROT13_BAD_LIKERT_JUDGE`
* `SAFETY_PII_ROT13_CRESCENDO_JAILBREAKING`
* `SAFETY_PII_ROT13_LINEAR_JAILBREAKING`
* `SAFETY_PII_ROT13_SEQUENTIAL_JAILBREAKING`
* `SAFETY_PII_ROT13_TREE_JAILBREAKING`
* `SAFETY_PRIVACY_VIOLATION_ROT13`
* `SAFETY_PRIVACY_VIOLATION_ROT13_BAD_LIKERT_JUDGE`
* `SAFETY_PRIVACY_VIOLATION_ROT13_CRESCENDO_JAILBREAKING`
* `SAFETY_PRIVACY_VIOLATION_ROT13_LINEAR_JAILBREAKING`
* `SAFETY_PRIVACY_VIOLATION_ROT13_SEQUENTIAL_JAILBREAKING`
* `SAFETY_PRIVACY_VIOLATION_ROT13_TREE_JAILBREAKING`
* `SECURITY_IDENTITY_SPOOFING_ROT13`
* `SECURITY_IDENTITY_SPOOFING_ROT13_BAD_LIKERT_JUDGE`
* `SECURITY_IDENTITY_SPOOFING_ROT13_CRESCENDO_JAILBREAKING`
* `SECURITY_IDENTITY_SPOOFING_ROT13_LINEAR_JAILBREAKING`
* `SECURITY_IDENTITY_SPOOFING_ROT13_SEQUENTIAL_JAILBREAKING`
* `SECURITY_IDENTITY_SPOOFING_ROT13_TREE_JAILBREAKING`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_ROT13`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_ROT13_BAD_LIKERT_JUDGE`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_ROT13_CRESCENDO_JAILBREAKING`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_ROT13_LINEAR_JAILBREAKING`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_ROT13_SEQUENTIAL_JAILBREAKING`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_ROT13_TREE_JAILBREAKING`

#### Roleplay

* `SAFETY_PII_ROLEPLAY`
* `SAFETY_PII_ROLEPLAY_BAD_LIKERT_JUDGE`
* `SAFETY_PII_ROLEPLAY_CRESCENDO_JAILBREAKING`
* `SAFETY_PII_ROLEPLAY_LINEAR_JAILBREAKING`
* `SAFETY_PII_ROLEPLAY_SEQUENTIAL_JAILBREAKING`
* `SAFETY_PII_ROLEPLAY_TREE_JAILBREAKING`
* `SAFETY_PRIVACY_VIOLATION_ROLEPLAY`
* `SAFETY_PRIVACY_VIOLATION_ROLEPLAY_BAD_LIKERT_JUDGE`
* `SAFETY_PRIVACY_VIOLATION_ROLEPLAY_CRESCENDO_JAILBREAKING`
* `SAFETY_PRIVACY_VIOLATION_ROLEPLAY_LINEAR_JAILBREAKING`
* `SAFETY_PRIVACY_VIOLATION_ROLEPLAY_SEQUENTIAL_JAILBREAKING`
* `SAFETY_PRIVACY_VIOLATION_ROLEPLAY_TREE_JAILBREAKING`
* `SECURITY_CROSS_SESSION_LEAKS_ROLEPLAY`
* `SECURITY_CROSS_SESSION_LEAKS_ROLEPLAY_BAD_LIKERT_JUDGE`
* `SECURITY_CROSS_SESSION_LEAKS_ROLEPLAY_CRESCENDO_JAILBREAKING`
* `SECURITY_CROSS_SESSION_LEAKS_ROLEPLAY_LINEAR_JAILBREAKING`
* `SECURITY_CROSS_SESSION_LEAKS_ROLEPLAY_SEQUENTIAL_JAILBREAKING`
* `SECURITY_CROSS_SESSION_LEAKS_ROLEPLAY_TREE_JAILBREAKING`
* `SECURITY_IDENTITY_SPOOFING_ROLEPLAY`
* `SECURITY_IDENTITY_SPOOFING_ROLEPLAY_BAD_LIKERT_JUDGE`
* `SECURITY_IDENTITY_SPOOFING_ROLEPLAY_CRESCENDO_JAILBREAKING`
* `SECURITY_IDENTITY_SPOOFING_ROLEPLAY_LINEAR_JAILBREAKING`
* `SECURITY_IDENTITY_SPOOFING_ROLEPLAY_SEQUENTIAL_JAILBREAKING`
* `SECURITY_IDENTITY_SPOOFING_ROLEPLAY_TREE_JAILBREAKING`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_ROLEPLAY`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_ROLEPLAY_BAD_LIKERT_JUDGE`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_ROLEPLAY_CRESCENDO_JAILBREAKING`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_ROLEPLAY_LINEAR_JAILBREAKING`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_ROLEPLAY_SEQUENTIAL_JAILBREAKING`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_ROLEPLAY_TREE_JAILBREAKING`

#### Semantic Manipulation

* `SAFETY_PII_SEMANTIC_MANIPULATION`
* `SAFETY_PII_SEMANTIC_MANIPULATION_BAD_LIKERT_JUDGE`
* `SAFETY_PII_SEMANTIC_MANIPULATION_CRESCENDO_JAILBREAKING`
* `SAFETY_PII_SEMANTIC_MANIPULATION_LINEAR_JAILBREAKING`
* `SAFETY_PII_SEMANTIC_MANIPULATION_SEQUENTIAL_JAILBREAKING`
* `SAFETY_PII_SEMANTIC_MANIPULATION_TREE_JAILBREAKING`
* `SAFETY_PRIVACY_VIOLATION_SEMANTIC_MANIPULATION`
* `SAFETY_PRIVACY_VIOLATION_SEMANTIC_MANIPULATION_BAD_LIKERT_JUDGE`
* `SAFETY_PRIVACY_VIOLATION_SEMANTIC_MANIPULATION_CRESCENDO_JAILBREAKING`
* `SAFETY_PRIVACY_VIOLATION_SEMANTIC_MANIPULATION_LINEAR_JAILBREAKING`
* `SAFETY_PRIVACY_VIOLATION_SEMANTIC_MANIPULATION_SEQUENTIAL_JAILBREAKING`
* `SAFETY_PRIVACY_VIOLATION_SEMANTIC_MANIPULATION_TREE_JAILBREAKING`
* `SECURITY_CROSS_SESSION_LEAKS_SEMANTIC_MANIPULATION`
* `SECURITY_CROSS_SESSION_LEAKS_SEMANTIC_MANIPULATION_BAD_LIKERT_JUDGE`
* `SECURITY_CROSS_SESSION_LEAKS_SEMANTIC_MANIPULATION_CRESCENDO_JAILBREAKING`
* `SECURITY_CROSS_SESSION_LEAKS_SEMANTIC_MANIPULATION_LINEAR_JAILBREAKING`
* `SECURITY_CROSS_SESSION_LEAKS_SEMANTIC_MANIPULATION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_CROSS_SESSION_LEAKS_SEMANTIC_MANIPULATION_TREE_JAILBREAKING`
* `SECURITY_IDENTITY_SPOOFING_SEMANTIC_MANIPULATION`
* `SECURITY_IDENTITY_SPOOFING_SEMANTIC_MANIPULATION_BAD_LIKERT_JUDGE`
* `SECURITY_IDENTITY_SPOOFING_SEMANTIC_MANIPULATION_CRESCENDO_JAILBREAKING`
* `SECURITY_IDENTITY_SPOOFING_SEMANTIC_MANIPULATION_LINEAR_JAILBREAKING`
* `SECURITY_IDENTITY_SPOOFING_SEMANTIC_MANIPULATION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_IDENTITY_SPOOFING_SEMANTIC_MANIPULATION_TREE_JAILBREAKING`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_SEMANTIC_MANIPULATION`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_SEMANTIC_MANIPULATION_BAD_LIKERT_JUDGE`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_SEMANTIC_MANIPULATION_CRESCENDO_JAILBREAKING`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_SEMANTIC_MANIPULATION_LINEAR_JAILBREAKING`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_SEMANTIC_MANIPULATION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_SEMANTIC_MANIPULATION_TREE_JAILBREAKING`

#### System Override

* `SAFETY_PII_SYSTEM_OVERRIDE`
* `SAFETY_PII_SYSTEM_OVERRIDE_BAD_LIKERT_JUDGE`
* `SAFETY_PII_SYSTEM_OVERRIDE_CRESCENDO_JAILBREAKING`
* `SAFETY_PII_SYSTEM_OVERRIDE_LINEAR_JAILBREAKING`
* `SAFETY_PII_SYSTEM_OVERRIDE_SEQUENTIAL_JAILBREAKING`
* `SAFETY_PII_SYSTEM_OVERRIDE_TREE_JAILBREAKING`
* `SAFETY_PRIVACY_VIOLATION_SYSTEM_OVERRIDE`
* `SAFETY_PRIVACY_VIOLATION_SYSTEM_OVERRIDE_BAD_LIKERT_JUDGE`
* `SAFETY_PRIVACY_VIOLATION_SYSTEM_OVERRIDE_CRESCENDO_JAILBREAKING`
* `SAFETY_PRIVACY_VIOLATION_SYSTEM_OVERRIDE_LINEAR_JAILBREAKING`
* `SAFETY_PRIVACY_VIOLATION_SYSTEM_OVERRIDE_SEQUENTIAL_JAILBREAKING`
* `SAFETY_PRIVACY_VIOLATION_SYSTEM_OVERRIDE_TREE_JAILBREAKING`
* `SECURITY_CROSS_SESSION_LEAKS_SYSTEM_OVERRIDE`
* `SECURITY_CROSS_SESSION_LEAKS_SYSTEM_OVERRIDE_BAD_LIKERT_JUDGE`
* `SECURITY_CROSS_SESSION_LEAKS_SYSTEM_OVERRIDE_CRESCENDO_JAILBREAKING`
* `SECURITY_CROSS_SESSION_LEAKS_SYSTEM_OVERRIDE_LINEAR_JAILBREAKING`
* `SECURITY_CROSS_SESSION_LEAKS_SYSTEM_OVERRIDE_SEQUENTIAL_JAILBREAKING`
* `SECURITY_CROSS_SESSION_LEAKS_SYSTEM_OVERRIDE_TREE_JAILBREAKING`
* `SECURITY_IDENTITY_SPOOFING_SYSTEM_OVERRIDE`
* `SECURITY_IDENTITY_SPOOFING_SYSTEM_OVERRIDE_BAD_LIKERT_JUDGE`
* `SECURITY_IDENTITY_SPOOFING_SYSTEM_OVERRIDE_CRESCENDO_JAILBREAKING`
* `SECURITY_IDENTITY_SPOOFING_SYSTEM_OVERRIDE_LINEAR_JAILBREAKING`
* `SECURITY_IDENTITY_SPOOFING_SYSTEM_OVERRIDE_SEQUENTIAL_JAILBREAKING`
* `SECURITY_IDENTITY_SPOOFING_SYSTEM_OVERRIDE_TREE_JAILBREAKING`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_SYSTEM_OVERRIDE`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_SYSTEM_OVERRIDE_BAD_LIKERT_JUDGE`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_SYSTEM_OVERRIDE_CRESCENDO_JAILBREAKING`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_SYSTEM_OVERRIDE_LINEAR_JAILBREAKING`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_SYSTEM_OVERRIDE_SEQUENTIAL_JAILBREAKING`
* `SECURITY_SENSITIVE_INFORMATION_DISCLOSURE_SYSTEM_OVERRIDE_TREE_JAILBREAKING`

***

### ASI04: Agentic Supply Chain Vulnerabilities

#### Base64

* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_BASE64`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_BASE64_BAD_LIKERT_JUDGE`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_BASE64_CRESCENDO_JAILBREAKING`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_BASE64_LINEAR_JAILBREAKING`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_BASE64_SEQUENTIAL_JAILBREAKING`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_BASE64_TREE_JAILBREAKING`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_BASE64`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_BASE64_BAD_LIKERT_JUDGE`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_BASE64_CRESCENDO_JAILBREAKING`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_BASE64_LINEAR_JAILBREAKING`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_BASE64_SEQUENTIAL_JAILBREAKING`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_BASE64_TREE_JAILBREAKING`
* `SECURITY_MODEL_THEFT_BASE64`
* `SECURITY_MODEL_THEFT_BASE64_BAD_LIKERT_JUDGE`
* `SECURITY_MODEL_THEFT_BASE64_CRESCENDO_JAILBREAKING`
* `SECURITY_MODEL_THEFT_BASE64_LINEAR_JAILBREAKING`
* `SECURITY_MODEL_THEFT_BASE64_SEQUENTIAL_JAILBREAKING`
* `SECURITY_MODEL_THEFT_BASE64_TREE_JAILBREAKING`
* `SECURITY_TRAINING_DATA_POISONING_BASE64`
* `SECURITY_TRAINING_DATA_POISONING_BASE64_BAD_LIKERT_JUDGE`
* `SECURITY_TRAINING_DATA_POISONING_BASE64_CRESCENDO_JAILBREAKING`
* `SECURITY_TRAINING_DATA_POISONING_BASE64_LINEAR_JAILBREAKING`
* `SECURITY_TRAINING_DATA_POISONING_BASE64_SEQUENTIAL_JAILBREAKING`
* `SECURITY_TRAINING_DATA_POISONING_BASE64_TREE_JAILBREAKING`

#### Context Poisoning

* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_CONTEXT_POISONING`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_CONTEXT_POISONING_BAD_LIKERT_JUDGE`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_CONTEXT_POISONING_CRESCENDO_JAILBREAKING`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_CONTEXT_POISONING_LINEAR_JAILBREAKING`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_CONTEXT_POISONING_SEQUENTIAL_JAILBREAKING`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_CONTEXT_POISONING_TREE_JAILBREAKING`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_CONTEXT_POISONING`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_CONTEXT_POISONING_BAD_LIKERT_JUDGE`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_CONTEXT_POISONING_CRESCENDO_JAILBREAKING`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_CONTEXT_POISONING_LINEAR_JAILBREAKING`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_CONTEXT_POISONING_SEQUENTIAL_JAILBREAKING`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_CONTEXT_POISONING_TREE_JAILBREAKING`
* `SECURITY_MODEL_THEFT_CONTEXT_POISONING`
* `SECURITY_MODEL_THEFT_CONTEXT_POISONING_BAD_LIKERT_JUDGE`
* `SECURITY_MODEL_THEFT_CONTEXT_POISONING_CRESCENDO_JAILBREAKING`
* `SECURITY_MODEL_THEFT_CONTEXT_POISONING_LINEAR_JAILBREAKING`
* `SECURITY_MODEL_THEFT_CONTEXT_POISONING_SEQUENTIAL_JAILBREAKING`
* `SECURITY_MODEL_THEFT_CONTEXT_POISONING_TREE_JAILBREAKING`
* `SECURITY_TRAINING_DATA_POISONING_CONTEXT_POISONING`
* `SECURITY_TRAINING_DATA_POISONING_CONTEXT_POISONING_BAD_LIKERT_JUDGE`
* `SECURITY_TRAINING_DATA_POISONING_CONTEXT_POISONING_CRESCENDO_JAILBREAKING`
* `SECURITY_TRAINING_DATA_POISONING_CONTEXT_POISONING_LINEAR_JAILBREAKING`
* `SECURITY_TRAINING_DATA_POISONING_CONTEXT_POISONING_SEQUENTIAL_JAILBREAKING`
* `SECURITY_TRAINING_DATA_POISONING_CONTEXT_POISONING_TREE_JAILBREAKING`

#### Goal Redirection

* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_GOAL_REDIRECTION`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_GOAL_REDIRECTION_BAD_LIKERT_JUDGE`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_GOAL_REDIRECTION_CRESCENDO_JAILBREAKING`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_GOAL_REDIRECTION_LINEAR_JAILBREAKING`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_GOAL_REDIRECTION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_GOAL_REDIRECTION_TREE_JAILBREAKING`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_GOAL_REDIRECTION`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_GOAL_REDIRECTION_BAD_LIKERT_JUDGE`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_GOAL_REDIRECTION_CRESCENDO_JAILBREAKING`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_GOAL_REDIRECTION_LINEAR_JAILBREAKING`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_GOAL_REDIRECTION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_GOAL_REDIRECTION_TREE_JAILBREAKING`
* `SECURITY_MODEL_THEFT_GOAL_REDIRECTION`
* `SECURITY_MODEL_THEFT_GOAL_REDIRECTION_BAD_LIKERT_JUDGE`
* `SECURITY_MODEL_THEFT_GOAL_REDIRECTION_CRESCENDO_JAILBREAKING`
* `SECURITY_MODEL_THEFT_GOAL_REDIRECTION_LINEAR_JAILBREAKING`
* `SECURITY_MODEL_THEFT_GOAL_REDIRECTION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_MODEL_THEFT_GOAL_REDIRECTION_TREE_JAILBREAKING`
* `SECURITY_TRAINING_DATA_POISONING_GOAL_REDIRECTION`
* `SECURITY_TRAINING_DATA_POISONING_GOAL_REDIRECTION_BAD_LIKERT_JUDGE`
* `SECURITY_TRAINING_DATA_POISONING_GOAL_REDIRECTION_CRESCENDO_JAILBREAKING`
* `SECURITY_TRAINING_DATA_POISONING_GOAL_REDIRECTION_LINEAR_JAILBREAKING`
* `SECURITY_TRAINING_DATA_POISONING_GOAL_REDIRECTION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_TRAINING_DATA_POISONING_GOAL_REDIRECTION_TREE_JAILBREAKING`

#### Input Bypass

* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_INPUT_BYPASS`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_INPUT_BYPASS_BAD_LIKERT_JUDGE`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_INPUT_BYPASS_CRESCENDO_JAILBREAKING`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_INPUT_BYPASS_LINEAR_JAILBREAKING`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_INPUT_BYPASS_SEQUENTIAL_JAILBREAKING`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_INPUT_BYPASS_TREE_JAILBREAKING`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_INPUT_BYPASS`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_INPUT_BYPASS_BAD_LIKERT_JUDGE`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_INPUT_BYPASS_CRESCENDO_JAILBREAKING`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_INPUT_BYPASS_LINEAR_JAILBREAKING`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_INPUT_BYPASS_SEQUENTIAL_JAILBREAKING`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_INPUT_BYPASS_TREE_JAILBREAKING`
* `SECURITY_MODEL_THEFT_INPUT_BYPASS`
* `SECURITY_MODEL_THEFT_INPUT_BYPASS_BAD_LIKERT_JUDGE`
* `SECURITY_MODEL_THEFT_INPUT_BYPASS_CRESCENDO_JAILBREAKING`
* `SECURITY_MODEL_THEFT_INPUT_BYPASS_LINEAR_JAILBREAKING`
* `SECURITY_MODEL_THEFT_INPUT_BYPASS_SEQUENTIAL_JAILBREAKING`
* `SECURITY_MODEL_THEFT_INPUT_BYPASS_TREE_JAILBREAKING`
* `SECURITY_TRAINING_DATA_POISONING_INPUT_BYPASS`
* `SECURITY_TRAINING_DATA_POISONING_INPUT_BYPASS_BAD_LIKERT_JUDGE`
* `SECURITY_TRAINING_DATA_POISONING_INPUT_BYPASS_CRESCENDO_JAILBREAKING`
* `SECURITY_TRAINING_DATA_POISONING_INPUT_BYPASS_LINEAR_JAILBREAKING`
* `SECURITY_TRAINING_DATA_POISONING_INPUT_BYPASS_SEQUENTIAL_JAILBREAKING`
* `SECURITY_TRAINING_DATA_POISONING_INPUT_BYPASS_TREE_JAILBREAKING`

#### Leetspeak

* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_LEETSPEAK`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_LEETSPEAK_BAD_LIKERT_JUDGE`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_LEETSPEAK_CRESCENDO_JAILBREAKING`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_LEETSPEAK_LINEAR_JAILBREAKING`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_LEETSPEAK_SEQUENTIAL_JAILBREAKING`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_LEETSPEAK_TREE_JAILBREAKING`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_LEETSPEAK`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_LEETSPEAK_BAD_LIKERT_JUDGE`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_LEETSPEAK_CRESCENDO_JAILBREAKING`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_LEETSPEAK_LINEAR_JAILBREAKING`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_LEETSPEAK_SEQUENTIAL_JAILBREAKING`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_LEETSPEAK_TREE_JAILBREAKING`
* `SECURITY_MODEL_THEFT_LEETSPEAK`
* `SECURITY_MODEL_THEFT_LEETSPEAK_BAD_LIKERT_JUDGE`
* `SECURITY_MODEL_THEFT_LEETSPEAK_CRESCENDO_JAILBREAKING`
* `SECURITY_MODEL_THEFT_LEETSPEAK_LINEAR_JAILBREAKING`
* `SECURITY_MODEL_THEFT_LEETSPEAK_SEQUENTIAL_JAILBREAKING`
* `SECURITY_MODEL_THEFT_LEETSPEAK_TREE_JAILBREAKING`
* `SECURITY_TRAINING_DATA_POISONING_LEETSPEAK`
* `SECURITY_TRAINING_DATA_POISONING_LEETSPEAK_BAD_LIKERT_JUDGE`
* `SECURITY_TRAINING_DATA_POISONING_LEETSPEAK_CRESCENDO_JAILBREAKING`
* `SECURITY_TRAINING_DATA_POISONING_LEETSPEAK_LINEAR_JAILBREAKING`
* `SECURITY_TRAINING_DATA_POISONING_LEETSPEAK_SEQUENTIAL_JAILBREAKING`
* `SECURITY_TRAINING_DATA_POISONING_LEETSPEAK_TREE_JAILBREAKING`

#### Math Problem

* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_MATH_PROBLEM`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_MATH_PROBLEM_BAD_LIKERT_JUDGE`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_MATH_PROBLEM_CRESCENDO_JAILBREAKING`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_MATH_PROBLEM_LINEAR_JAILBREAKING`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_MATH_PROBLEM_SEQUENTIAL_JAILBREAKING`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_MATH_PROBLEM_TREE_JAILBREAKING`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_MATH_PROBLEM`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_MATH_PROBLEM_BAD_LIKERT_JUDGE`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_MATH_PROBLEM_CRESCENDO_JAILBREAKING`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_MATH_PROBLEM_LINEAR_JAILBREAKING`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_MATH_PROBLEM_SEQUENTIAL_JAILBREAKING`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_MATH_PROBLEM_TREE_JAILBREAKING`
* `SECURITY_MODEL_THEFT_MATH_PROBLEM`
* `SECURITY_MODEL_THEFT_MATH_PROBLEM_BAD_LIKERT_JUDGE`
* `SECURITY_MODEL_THEFT_MATH_PROBLEM_CRESCENDO_JAILBREAKING`
* `SECURITY_MODEL_THEFT_MATH_PROBLEM_LINEAR_JAILBREAKING`
* `SECURITY_MODEL_THEFT_MATH_PROBLEM_SEQUENTIAL_JAILBREAKING`
* `SECURITY_MODEL_THEFT_MATH_PROBLEM_TREE_JAILBREAKING`
* `SECURITY_TRAINING_DATA_POISONING_MATH_PROBLEM`
* `SECURITY_TRAINING_DATA_POISONING_MATH_PROBLEM_BAD_LIKERT_JUDGE`
* `SECURITY_TRAINING_DATA_POISONING_MATH_PROBLEM_CRESCENDO_JAILBREAKING`
* `SECURITY_TRAINING_DATA_POISONING_MATH_PROBLEM_LINEAR_JAILBREAKING`
* `SECURITY_TRAINING_DATA_POISONING_MATH_PROBLEM_SEQUENTIAL_JAILBREAKING`
* `SECURITY_TRAINING_DATA_POISONING_MATH_PROBLEM_TREE_JAILBREAKING`

#### Multilingual

* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_MULTILINGUAL`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_MULTILINGUAL_BAD_LIKERT_JUDGE`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_MULTILINGUAL_CRESCENDO_JAILBREAKING`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_MULTILINGUAL_LINEAR_JAILBREAKING`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_MULTILINGUAL_SEQUENTIAL_JAILBREAKING`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_MULTILINGUAL_TREE_JAILBREAKING`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_MULTILINGUAL`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_MULTILINGUAL_BAD_LIKERT_JUDGE`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_MULTILINGUAL_CRESCENDO_JAILBREAKING`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_MULTILINGUAL_LINEAR_JAILBREAKING`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_MULTILINGUAL_SEQUENTIAL_JAILBREAKING`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_MULTILINGUAL_TREE_JAILBREAKING`
* `SECURITY_MODEL_THEFT_MULTILINGUAL`
* `SECURITY_MODEL_THEFT_MULTILINGUAL_BAD_LIKERT_JUDGE`
* `SECURITY_MODEL_THEFT_MULTILINGUAL_CRESCENDO_JAILBREAKING`
* `SECURITY_MODEL_THEFT_MULTILINGUAL_LINEAR_JAILBREAKING`
* `SECURITY_MODEL_THEFT_MULTILINGUAL_SEQUENTIAL_JAILBREAKING`
* `SECURITY_MODEL_THEFT_MULTILINGUAL_TREE_JAILBREAKING`
* `SECURITY_TRAINING_DATA_POISONING_MULTILINGUAL`
* `SECURITY_TRAINING_DATA_POISONING_MULTILINGUAL_BAD_LIKERT_JUDGE`
* `SECURITY_TRAINING_DATA_POISONING_MULTILINGUAL_CRESCENDO_JAILBREAKING`
* `SECURITY_TRAINING_DATA_POISONING_MULTILINGUAL_LINEAR_JAILBREAKING`
* `SECURITY_TRAINING_DATA_POISONING_MULTILINGUAL_SEQUENTIAL_JAILBREAKING`
* `SECURITY_TRAINING_DATA_POISONING_MULTILINGUAL_TREE_JAILBREAKING`

#### Permission Escalation

* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_PERMISSION_ESCALATION`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_PERMISSION_ESCALATION_BAD_LIKERT_JUDGE`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_PERMISSION_ESCALATION_CRESCENDO_JAILBREAKING`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_PERMISSION_ESCALATION_LINEAR_JAILBREAKING`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_PERMISSION_ESCALATION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_PERMISSION_ESCALATION_TREE_JAILBREAKING`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_PERMISSION_ESCALATION`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_PERMISSION_ESCALATION_BAD_LIKERT_JUDGE`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_PERMISSION_ESCALATION_CRESCENDO_JAILBREAKING`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_PERMISSION_ESCALATION_LINEAR_JAILBREAKING`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_PERMISSION_ESCALATION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_PERMISSION_ESCALATION_TREE_JAILBREAKING`
* `SECURITY_MODEL_THEFT_PERMISSION_ESCALATION`
* `SECURITY_MODEL_THEFT_PERMISSION_ESCALATION_BAD_LIKERT_JUDGE`
* `SECURITY_MODEL_THEFT_PERMISSION_ESCALATION_CRESCENDO_JAILBREAKING`
* `SECURITY_MODEL_THEFT_PERMISSION_ESCALATION_LINEAR_JAILBREAKING`
* `SECURITY_MODEL_THEFT_PERMISSION_ESCALATION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_MODEL_THEFT_PERMISSION_ESCALATION_TREE_JAILBREAKING`
* `SECURITY_TRAINING_DATA_POISONING_PERMISSION_ESCALATION`
* `SECURITY_TRAINING_DATA_POISONING_PERMISSION_ESCALATION_BAD_LIKERT_JUDGE`
* `SECURITY_TRAINING_DATA_POISONING_PERMISSION_ESCALATION_CRESCENDO_JAILBREAKING`
* `SECURITY_TRAINING_DATA_POISONING_PERMISSION_ESCALATION_LINEAR_JAILBREAKING`
* `SECURITY_TRAINING_DATA_POISONING_PERMISSION_ESCALATION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_TRAINING_DATA_POISONING_PERMISSION_ESCALATION_TREE_JAILBREAKING`

#### Prompt Injection

* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_PROMPT_INJECTION`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_PROMPT_INJECTION_BAD_LIKERT_JUDGE`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_PROMPT_INJECTION_CRESCENDO_JAILBREAKING`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_PROMPT_INJECTION_LINEAR_JAILBREAKING`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_PROMPT_INJECTION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_PROMPT_INJECTION_TREE_JAILBREAKING`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_PROMPT_INJECTION`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_PROMPT_INJECTION_BAD_LIKERT_JUDGE`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_PROMPT_INJECTION_CRESCENDO_JAILBREAKING`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_PROMPT_INJECTION_LINEAR_JAILBREAKING`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_PROMPT_INJECTION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_PROMPT_INJECTION_TREE_JAILBREAKING`
* `SECURITY_MODEL_THEFT_PROMPT_INJECTION`
* `SECURITY_MODEL_THEFT_PROMPT_INJECTION_BAD_LIKERT_JUDGE`
* `SECURITY_MODEL_THEFT_PROMPT_INJECTION_CRESCENDO_JAILBREAKING`
* `SECURITY_MODEL_THEFT_PROMPT_INJECTION_LINEAR_JAILBREAKING`
* `SECURITY_MODEL_THEFT_PROMPT_INJECTION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_MODEL_THEFT_PROMPT_INJECTION_TREE_JAILBREAKING`
* `SECURITY_TRAINING_DATA_POISONING_PROMPT_INJECTION`
* `SECURITY_TRAINING_DATA_POISONING_PROMPT_INJECTION_BAD_LIKERT_JUDGE`
* `SECURITY_TRAINING_DATA_POISONING_PROMPT_INJECTION_CRESCENDO_JAILBREAKING`
* `SECURITY_TRAINING_DATA_POISONING_PROMPT_INJECTION_LINEAR_JAILBREAKING`
* `SECURITY_TRAINING_DATA_POISONING_PROMPT_INJECTION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_TRAINING_DATA_POISONING_PROMPT_INJECTION_TREE_JAILBREAKING`

#### ROT13

* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_ROT13`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_ROT13_BAD_LIKERT_JUDGE`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_ROT13_CRESCENDO_JAILBREAKING`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_ROT13_LINEAR_JAILBREAKING`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_ROT13_SEQUENTIAL_JAILBREAKING`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_ROT13_TREE_JAILBREAKING`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_ROT13`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_ROT13_BAD_LIKERT_JUDGE`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_ROT13_CRESCENDO_JAILBREAKING`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_ROT13_LINEAR_JAILBREAKING`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_ROT13_SEQUENTIAL_JAILBREAKING`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_ROT13_TREE_JAILBREAKING`
* `SECURITY_MODEL_THEFT_ROT13`
* `SECURITY_MODEL_THEFT_ROT13_BAD_LIKERT_JUDGE`
* `SECURITY_MODEL_THEFT_ROT13_CRESCENDO_JAILBREAKING`
* `SECURITY_MODEL_THEFT_ROT13_LINEAR_JAILBREAKING`
* `SECURITY_MODEL_THEFT_ROT13_SEQUENTIAL_JAILBREAKING`
* `SECURITY_MODEL_THEFT_ROT13_TREE_JAILBREAKING`
* `SECURITY_TRAINING_DATA_POISONING_ROT13`
* `SECURITY_TRAINING_DATA_POISONING_ROT13_BAD_LIKERT_JUDGE`
* `SECURITY_TRAINING_DATA_POISONING_ROT13_CRESCENDO_JAILBREAKING`
* `SECURITY_TRAINING_DATA_POISONING_ROT13_LINEAR_JAILBREAKING`
* `SECURITY_TRAINING_DATA_POISONING_ROT13_SEQUENTIAL_JAILBREAKING`
* `SECURITY_TRAINING_DATA_POISONING_ROT13_TREE_JAILBREAKING`

#### Roleplay

* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_ROLEPLAY`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_ROLEPLAY_BAD_LIKERT_JUDGE`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_ROLEPLAY_CRESCENDO_JAILBREAKING`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_ROLEPLAY_LINEAR_JAILBREAKING`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_ROLEPLAY_SEQUENTIAL_JAILBREAKING`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_ROLEPLAY_TREE_JAILBREAKING`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_ROLEPLAY`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_ROLEPLAY_BAD_LIKERT_JUDGE`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_ROLEPLAY_CRESCENDO_JAILBREAKING`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_ROLEPLAY_LINEAR_JAILBREAKING`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_ROLEPLAY_SEQUENTIAL_JAILBREAKING`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_ROLEPLAY_TREE_JAILBREAKING`
* `SECURITY_MODEL_THEFT_ROLEPLAY`
* `SECURITY_MODEL_THEFT_ROLEPLAY_BAD_LIKERT_JUDGE`
* `SECURITY_MODEL_THEFT_ROLEPLAY_CRESCENDO_JAILBREAKING`
* `SECURITY_MODEL_THEFT_ROLEPLAY_LINEAR_JAILBREAKING`
* `SECURITY_MODEL_THEFT_ROLEPLAY_SEQUENTIAL_JAILBREAKING`
* `SECURITY_MODEL_THEFT_ROLEPLAY_TREE_JAILBREAKING`
* `SECURITY_TRAINING_DATA_POISONING_ROLEPLAY`
* `SECURITY_TRAINING_DATA_POISONING_ROLEPLAY_BAD_LIKERT_JUDGE`
* `SECURITY_TRAINING_DATA_POISONING_ROLEPLAY_CRESCENDO_JAILBREAKING`
* `SECURITY_TRAINING_DATA_POISONING_ROLEPLAY_LINEAR_JAILBREAKING`
* `SECURITY_TRAINING_DATA_POISONING_ROLEPLAY_SEQUENTIAL_JAILBREAKING`
* `SECURITY_TRAINING_DATA_POISONING_ROLEPLAY_TREE_JAILBREAKING`

#### Semantic Manipulation

* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_SEMANTIC_MANIPULATION`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_SEMANTIC_MANIPULATION_BAD_LIKERT_JUDGE`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_SEMANTIC_MANIPULATION_CRESCENDO_JAILBREAKING`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_SEMANTIC_MANIPULATION_LINEAR_JAILBREAKING`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_SEMANTIC_MANIPULATION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_SEMANTIC_MANIPULATION_TREE_JAILBREAKING`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_SEMANTIC_MANIPULATION`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_SEMANTIC_MANIPULATION_BAD_LIKERT_JUDGE`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_SEMANTIC_MANIPULATION_CRESCENDO_JAILBREAKING`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_SEMANTIC_MANIPULATION_LINEAR_JAILBREAKING`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_SEMANTIC_MANIPULATION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_SEMANTIC_MANIPULATION_TREE_JAILBREAKING`
* `SECURITY_MODEL_THEFT_SEMANTIC_MANIPULATION`
* `SECURITY_MODEL_THEFT_SEMANTIC_MANIPULATION_BAD_LIKERT_JUDGE`
* `SECURITY_MODEL_THEFT_SEMANTIC_MANIPULATION_CRESCENDO_JAILBREAKING`
* `SECURITY_MODEL_THEFT_SEMANTIC_MANIPULATION_LINEAR_JAILBREAKING`
* `SECURITY_MODEL_THEFT_SEMANTIC_MANIPULATION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_MODEL_THEFT_SEMANTIC_MANIPULATION_TREE_JAILBREAKING`
* `SECURITY_TRAINING_DATA_POISONING_SEMANTIC_MANIPULATION`
* `SECURITY_TRAINING_DATA_POISONING_SEMANTIC_MANIPULATION_BAD_LIKERT_JUDGE`
* `SECURITY_TRAINING_DATA_POISONING_SEMANTIC_MANIPULATION_CRESCENDO_JAILBREAKING`
* `SECURITY_TRAINING_DATA_POISONING_SEMANTIC_MANIPULATION_LINEAR_JAILBREAKING`
* `SECURITY_TRAINING_DATA_POISONING_SEMANTIC_MANIPULATION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_TRAINING_DATA_POISONING_SEMANTIC_MANIPULATION_TREE_JAILBREAKING`

#### System Override

* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_SYSTEM_OVERRIDE`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_SYSTEM_OVERRIDE_BAD_LIKERT_JUDGE`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_SYSTEM_OVERRIDE_CRESCENDO_JAILBREAKING`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_SYSTEM_OVERRIDE_LINEAR_JAILBREAKING`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_SYSTEM_OVERRIDE_SEQUENTIAL_JAILBREAKING`
* `SECURITY_AGENTIC_SUPPLY_CHAIN_VULNERABILITIES_SYSTEM_OVERRIDE_TREE_JAILBREAKING`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_SYSTEM_OVERRIDE`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_SYSTEM_OVERRIDE_BAD_LIKERT_JUDGE`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_SYSTEM_OVERRIDE_CRESCENDO_JAILBREAKING`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_SYSTEM_OVERRIDE_LINEAR_JAILBREAKING`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_SYSTEM_OVERRIDE_SEQUENTIAL_JAILBREAKING`
* `SECURITY_MALICIOUS_RESOURCE_FETCHING_SYSTEM_OVERRIDE_TREE_JAILBREAKING`
* `SECURITY_MODEL_THEFT_SYSTEM_OVERRIDE`
* `SECURITY_MODEL_THEFT_SYSTEM_OVERRIDE_BAD_LIKERT_JUDGE`
* `SECURITY_MODEL_THEFT_SYSTEM_OVERRIDE_CRESCENDO_JAILBREAKING`
* `SECURITY_MODEL_THEFT_SYSTEM_OVERRIDE_LINEAR_JAILBREAKING`
* `SECURITY_MODEL_THEFT_SYSTEM_OVERRIDE_SEQUENTIAL_JAILBREAKING`
* `SECURITY_MODEL_THEFT_SYSTEM_OVERRIDE_TREE_JAILBREAKING`
* `SECURITY_TRAINING_DATA_POISONING_SYSTEM_OVERRIDE`
* `SECURITY_TRAINING_DATA_POISONING_SYSTEM_OVERRIDE_BAD_LIKERT_JUDGE`
* `SECURITY_TRAINING_DATA_POISONING_SYSTEM_OVERRIDE_CRESCENDO_JAILBREAKING`
* `SECURITY_TRAINING_DATA_POISONING_SYSTEM_OVERRIDE_LINEAR_JAILBREAKING`
* `SECURITY_TRAINING_DATA_POISONING_SYSTEM_OVERRIDE_SEQUENTIAL_JAILBREAKING`
* `SECURITY_TRAINING_DATA_POISONING_SYSTEM_OVERRIDE_TREE_JAILBREAKING`

***

### ASI05: Unexpected Code Execution (RCE)

#### Base64

* `SECURITY_CODE_EXECUTION_BASE64`
* `SECURITY_CODE_EXECUTION_BASE64_BAD_LIKERT_JUDGE`
* `SECURITY_CODE_EXECUTION_BASE64_CRESCENDO_JAILBREAKING`
* `SECURITY_CODE_EXECUTION_BASE64_LINEAR_JAILBREAKING`
* `SECURITY_CODE_EXECUTION_BASE64_SEQUENTIAL_JAILBREAKING`
* `SECURITY_CODE_EXECUTION_BASE64_TREE_JAILBREAKING`
* `SECURITY_PHISHING_BASE64`
* `SECURITY_PHISHING_BASE64_BAD_LIKERT_JUDGE`
* `SECURITY_PHISHING_BASE64_CRESCENDO_JAILBREAKING`
* `SECURITY_PHISHING_BASE64_LINEAR_JAILBREAKING`
* `SECURITY_PHISHING_BASE64_SEQUENTIAL_JAILBREAKING`
* `SECURITY_PHISHING_BASE64_TREE_JAILBREAKING`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_BASE64`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_BASE64_BAD_LIKERT_JUDGE`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_BASE64_CRESCENDO_JAILBREAKING`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_BASE64_LINEAR_JAILBREAKING`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_BASE64_SEQUENTIAL_JAILBREAKING`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_BASE64_TREE_JAILBREAKING`
* `SECURITY_WEB_INJECTION_BASE64`
* `SECURITY_WEB_INJECTION_BASE64_BAD_LIKERT_JUDGE`
* `SECURITY_WEB_INJECTION_BASE64_CRESCENDO_JAILBREAKING`
* `SECURITY_WEB_INJECTION_BASE64_LINEAR_JAILBREAKING`
* `SECURITY_WEB_INJECTION_BASE64_SEQUENTIAL_JAILBREAKING`
* `SECURITY_WEB_INJECTION_BASE64_TREE_JAILBREAKING`
* `SECURITY_XSS_BASE64`
* `SECURITY_XSS_BASE64_BAD_LIKERT_JUDGE`
* `SECURITY_XSS_BASE64_CRESCENDO_JAILBREAKING`
* `SECURITY_XSS_BASE64_LINEAR_JAILBREAKING`
* `SECURITY_XSS_BASE64_SEQUENTIAL_JAILBREAKING`
* `SECURITY_XSS_BASE64_TREE_JAILBREAKING`

#### Context Poisoning

* `SECURITY_CODE_EXECUTION_CONTEXT_POISONING`
* `SECURITY_CODE_EXECUTION_CONTEXT_POISONING_BAD_LIKERT_JUDGE`
* `SECURITY_CODE_EXECUTION_CONTEXT_POISONING_CRESCENDO_JAILBREAKING`
* `SECURITY_CODE_EXECUTION_CONTEXT_POISONING_LINEAR_JAILBREAKING`
* `SECURITY_CODE_EXECUTION_CONTEXT_POISONING_SEQUENTIAL_JAILBREAKING`
* `SECURITY_CODE_EXECUTION_CONTEXT_POISONING_TREE_JAILBREAKING`
* `SECURITY_PHISHING_CONTEXT_POISONING`
* `SECURITY_PHISHING_CONTEXT_POISONING_BAD_LIKERT_JUDGE`
* `SECURITY_PHISHING_CONTEXT_POISONING_CRESCENDO_JAILBREAKING`
* `SECURITY_PHISHING_CONTEXT_POISONING_LINEAR_JAILBREAKING`
* `SECURITY_PHISHING_CONTEXT_POISONING_SEQUENTIAL_JAILBREAKING`
* `SECURITY_PHISHING_CONTEXT_POISONING_TREE_JAILBREAKING`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_CONTEXT_POISONING`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_CONTEXT_POISONING_BAD_LIKERT_JUDGE`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_CONTEXT_POISONING_CRESCENDO_JAILBREAKING`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_CONTEXT_POISONING_LINEAR_JAILBREAKING`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_CONTEXT_POISONING_SEQUENTIAL_JAILBREAKING`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_CONTEXT_POISONING_TREE_JAILBREAKING`
* `SECURITY_WEB_INJECTION_CONTEXT_POISONING`
* `SECURITY_WEB_INJECTION_CONTEXT_POISONING_BAD_LIKERT_JUDGE`
* `SECURITY_WEB_INJECTION_CONTEXT_POISONING_CRESCENDO_JAILBREAKING`
* `SECURITY_WEB_INJECTION_CONTEXT_POISONING_LINEAR_JAILBREAKING`
* `SECURITY_WEB_INJECTION_CONTEXT_POISONING_SEQUENTIAL_JAILBREAKING`
* `SECURITY_WEB_INJECTION_CONTEXT_POISONING_TREE_JAILBREAKING`
* `SECURITY_XSS_CONTEXT_POISONING`
* `SECURITY_XSS_CONTEXT_POISONING_BAD_LIKERT_JUDGE`
* `SECURITY_XSS_CONTEXT_POISONING_CRESCENDO_JAILBREAKING`
* `SECURITY_XSS_CONTEXT_POISONING_LINEAR_JAILBREAKING`
* `SECURITY_XSS_CONTEXT_POISONING_SEQUENTIAL_JAILBREAKING`
* `SECURITY_XSS_CONTEXT_POISONING_TREE_JAILBREAKING`

#### Goal Redirection

* `SECURITY_CODE_EXECUTION_GOAL_REDIRECTION`
* `SECURITY_CODE_EXECUTION_GOAL_REDIRECTION_BAD_LIKERT_JUDGE`
* `SECURITY_CODE_EXECUTION_GOAL_REDIRECTION_CRESCENDO_JAILBREAKING`
* `SECURITY_CODE_EXECUTION_GOAL_REDIRECTION_LINEAR_JAILBREAKING`
* `SECURITY_CODE_EXECUTION_GOAL_REDIRECTION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_CODE_EXECUTION_GOAL_REDIRECTION_TREE_JAILBREAKING`
* `SECURITY_PHISHING_GOAL_REDIRECTION`
* `SECURITY_PHISHING_GOAL_REDIRECTION_BAD_LIKERT_JUDGE`
* `SECURITY_PHISHING_GOAL_REDIRECTION_CRESCENDO_JAILBREAKING`
* `SECURITY_PHISHING_GOAL_REDIRECTION_LINEAR_JAILBREAKING`
* `SECURITY_PHISHING_GOAL_REDIRECTION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_PHISHING_GOAL_REDIRECTION_TREE_JAILBREAKING`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_GOAL_REDIRECTION`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_GOAL_REDIRECTION_BAD_LIKERT_JUDGE`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_GOAL_REDIRECTION_CRESCENDO_JAILBREAKING`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_GOAL_REDIRECTION_LINEAR_JAILBREAKING`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_GOAL_REDIRECTION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_GOAL_REDIRECTION_TREE_JAILBREAKING`
* `SECURITY_WEB_INJECTION_GOAL_REDIRECTION`
* `SECURITY_WEB_INJECTION_GOAL_REDIRECTION_BAD_LIKERT_JUDGE`
* `SECURITY_WEB_INJECTION_GOAL_REDIRECTION_CRESCENDO_JAILBREAKING`
* `SECURITY_WEB_INJECTION_GOAL_REDIRECTION_LINEAR_JAILBREAKING`
* `SECURITY_WEB_INJECTION_GOAL_REDIRECTION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_WEB_INJECTION_GOAL_REDIRECTION_TREE_JAILBREAKING`
* `SECURITY_XSS_GOAL_REDIRECTION`
* `SECURITY_XSS_GOAL_REDIRECTION_BAD_LIKERT_JUDGE`
* `SECURITY_XSS_GOAL_REDIRECTION_CRESCENDO_JAILBREAKING`
* `SECURITY_XSS_GOAL_REDIRECTION_LINEAR_JAILBREAKING`
* `SECURITY_XSS_GOAL_REDIRECTION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_XSS_GOAL_REDIRECTION_TREE_JAILBREAKING`

#### Input Bypass

* `SECURITY_CODE_EXECUTION_INPUT_BYPASS`
* `SECURITY_CODE_EXECUTION_INPUT_BYPASS_BAD_LIKERT_JUDGE`
* `SECURITY_CODE_EXECUTION_INPUT_BYPASS_CRESCENDO_JAILBREAKING`
* `SECURITY_CODE_EXECUTION_INPUT_BYPASS_LINEAR_JAILBREAKING`
* `SECURITY_CODE_EXECUTION_INPUT_BYPASS_SEQUENTIAL_JAILBREAKING`
* `SECURITY_CODE_EXECUTION_INPUT_BYPASS_TREE_JAILBREAKING`
* `SECURITY_PHISHING_INPUT_BYPASS`
* `SECURITY_PHISHING_INPUT_BYPASS_BAD_LIKERT_JUDGE`
* `SECURITY_PHISHING_INPUT_BYPASS_CRESCENDO_JAILBREAKING`
* `SECURITY_PHISHING_INPUT_BYPASS_LINEAR_JAILBREAKING`
* `SECURITY_PHISHING_INPUT_BYPASS_SEQUENTIAL_JAILBREAKING`
* `SECURITY_PHISHING_INPUT_BYPASS_TREE_JAILBREAKING`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_INPUT_BYPASS`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_INPUT_BYPASS_BAD_LIKERT_JUDGE`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_INPUT_BYPASS_CRESCENDO_JAILBREAKING`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_INPUT_BYPASS_LINEAR_JAILBREAKING`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_INPUT_BYPASS_SEQUENTIAL_JAILBREAKING`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_INPUT_BYPASS_TREE_JAILBREAKING`
* `SECURITY_WEB_INJECTION_INPUT_BYPASS`
* `SECURITY_WEB_INJECTION_INPUT_BYPASS_BAD_LIKERT_JUDGE`
* `SECURITY_WEB_INJECTION_INPUT_BYPASS_CRESCENDO_JAILBREAKING`
* `SECURITY_WEB_INJECTION_INPUT_BYPASS_LINEAR_JAILBREAKING`
* `SECURITY_WEB_INJECTION_INPUT_BYPASS_SEQUENTIAL_JAILBREAKING`
* `SECURITY_WEB_INJECTION_INPUT_BYPASS_TREE_JAILBREAKING`
* `SECURITY_XSS_INPUT_BYPASS`
* `SECURITY_XSS_INPUT_BYPASS_BAD_LIKERT_JUDGE`
* `SECURITY_XSS_INPUT_BYPASS_CRESCENDO_JAILBREAKING`
* `SECURITY_XSS_INPUT_BYPASS_LINEAR_JAILBREAKING`
* `SECURITY_XSS_INPUT_BYPASS_SEQUENTIAL_JAILBREAKING`
* `SECURITY_XSS_INPUT_BYPASS_TREE_JAILBREAKING`

#### Leetspeak

* `SECURITY_CODE_EXECUTION_LEETSPEAK`
* `SECURITY_CODE_EXECUTION_LEETSPEAK_BAD_LIKERT_JUDGE`
* `SECURITY_CODE_EXECUTION_LEETSPEAK_CRESCENDO_JAILBREAKING`
* `SECURITY_CODE_EXECUTION_LEETSPEAK_LINEAR_JAILBREAKING`
* `SECURITY_CODE_EXECUTION_LEETSPEAK_SEQUENTIAL_JAILBREAKING`
* `SECURITY_CODE_EXECUTION_LEETSPEAK_TREE_JAILBREAKING`
* `SECURITY_PHISHING_LEETSPEAK`
* `SECURITY_PHISHING_LEETSPEAK_BAD_LIKERT_JUDGE`
* `SECURITY_PHISHING_LEETSPEAK_CRESCENDO_JAILBREAKING`
* `SECURITY_PHISHING_LEETSPEAK_LINEAR_JAILBREAKING`
* `SECURITY_PHISHING_LEETSPEAK_SEQUENTIAL_JAILBREAKING`
* `SECURITY_PHISHING_LEETSPEAK_TREE_JAILBREAKING`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_LEETSPEAK`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_LEETSPEAK_BAD_LIKERT_JUDGE`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_LEETSPEAK_CRESCENDO_JAILBREAKING`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_LEETSPEAK_LINEAR_JAILBREAKING`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_LEETSPEAK_SEQUENTIAL_JAILBREAKING`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_LEETSPEAK_TREE_JAILBREAKING`
* `SECURITY_WEB_INJECTION_LEETSPEAK`
* `SECURITY_WEB_INJECTION_LEETSPEAK_BAD_LIKERT_JUDGE`
* `SECURITY_WEB_INJECTION_LEETSPEAK_CRESCENDO_JAILBREAKING`
* `SECURITY_WEB_INJECTION_LEETSPEAK_LINEAR_JAILBREAKING`
* `SECURITY_WEB_INJECTION_LEETSPEAK_SEQUENTIAL_JAILBREAKING`
* `SECURITY_WEB_INJECTION_LEETSPEAK_TREE_JAILBREAKING`
* `SECURITY_XSS_LEETSPEAK`
* `SECURITY_XSS_LEETSPEAK_BAD_LIKERT_JUDGE`
* `SECURITY_XSS_LEETSPEAK_CRESCENDO_JAILBREAKING`
* `SECURITY_XSS_LEETSPEAK_LINEAR_JAILBREAKING`
* `SECURITY_XSS_LEETSPEAK_SEQUENTIAL_JAILBREAKING`
* `SECURITY_XSS_LEETSPEAK_TREE_JAILBREAKING`

#### Math Problem

* `SECURITY_CODE_EXECUTION_MATH_PROBLEM`
* `SECURITY_CODE_EXECUTION_MATH_PROBLEM_BAD_LIKERT_JUDGE`
* `SECURITY_CODE_EXECUTION_MATH_PROBLEM_CRESCENDO_JAILBREAKING`
* `SECURITY_CODE_EXECUTION_MATH_PROBLEM_LINEAR_JAILBREAKING`
* `SECURITY_CODE_EXECUTION_MATH_PROBLEM_SEQUENTIAL_JAILBREAKING`
* `SECURITY_CODE_EXECUTION_MATH_PROBLEM_TREE_JAILBREAKING`
* `SECURITY_PHISHING_MATH_PROBLEM`
* `SECURITY_PHISHING_MATH_PROBLEM_BAD_LIKERT_JUDGE`
* `SECURITY_PHISHING_MATH_PROBLEM_CRESCENDO_JAILBREAKING`
* `SECURITY_PHISHING_MATH_PROBLEM_LINEAR_JAILBREAKING`
* `SECURITY_PHISHING_MATH_PROBLEM_SEQUENTIAL_JAILBREAKING`
* `SECURITY_PHISHING_MATH_PROBLEM_TREE_JAILBREAKING`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_MATH_PROBLEM`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_MATH_PROBLEM_BAD_LIKERT_JUDGE`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_MATH_PROBLEM_CRESCENDO_JAILBREAKING`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_MATH_PROBLEM_LINEAR_JAILBREAKING`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_MATH_PROBLEM_SEQUENTIAL_JAILBREAKING`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_MATH_PROBLEM_TREE_JAILBREAKING`
* `SECURITY_WEB_INJECTION_MATH_PROBLEM`
* `SECURITY_WEB_INJECTION_MATH_PROBLEM_BAD_LIKERT_JUDGE`
* `SECURITY_WEB_INJECTION_MATH_PROBLEM_CRESCENDO_JAILBREAKING`
* `SECURITY_WEB_INJECTION_MATH_PROBLEM_LINEAR_JAILBREAKING`
* `SECURITY_WEB_INJECTION_MATH_PROBLEM_SEQUENTIAL_JAILBREAKING`
* `SECURITY_WEB_INJECTION_MATH_PROBLEM_TREE_JAILBREAKING`
* `SECURITY_XSS_MATH_PROBLEM`
* `SECURITY_XSS_MATH_PROBLEM_BAD_LIKERT_JUDGE`
* `SECURITY_XSS_MATH_PROBLEM_CRESCENDO_JAILBREAKING`
* `SECURITY_XSS_MATH_PROBLEM_LINEAR_JAILBREAKING`
* `SECURITY_XSS_MATH_PROBLEM_SEQUENTIAL_JAILBREAKING`
* `SECURITY_XSS_MATH_PROBLEM_TREE_JAILBREAKING`

#### Multilingual

* `SECURITY_CODE_EXECUTION_MULTILINGUAL`
* `SECURITY_CODE_EXECUTION_MULTILINGUAL_BAD_LIKERT_JUDGE`
* `SECURITY_CODE_EXECUTION_MULTILINGUAL_CRESCENDO_JAILBREAKING`
* `SECURITY_CODE_EXECUTION_MULTILINGUAL_LINEAR_JAILBREAKING`
* `SECURITY_CODE_EXECUTION_MULTILINGUAL_SEQUENTIAL_JAILBREAKING`
* `SECURITY_CODE_EXECUTION_MULTILINGUAL_TREE_JAILBREAKING`
* `SECURITY_PHISHING_MULTILINGUAL`
* `SECURITY_PHISHING_MULTILINGUAL_BAD_LIKERT_JUDGE`
* `SECURITY_PHISHING_MULTILINGUAL_CRESCENDO_JAILBREAKING`
* `SECURITY_PHISHING_MULTILINGUAL_LINEAR_JAILBREAKING`
* `SECURITY_PHISHING_MULTILINGUAL_SEQUENTIAL_JAILBREAKING`
* `SECURITY_PHISHING_MULTILINGUAL_TREE_JAILBREAKING`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_MULTILINGUAL`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_MULTILINGUAL_BAD_LIKERT_JUDGE`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_MULTILINGUAL_CRESCENDO_JAILBREAKING`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_MULTILINGUAL_LINEAR_JAILBREAKING`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_MULTILINGUAL_SEQUENTIAL_JAILBREAKING`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_MULTILINGUAL_TREE_JAILBREAKING`
* `SECURITY_WEB_INJECTION_MULTILINGUAL`
* `SECURITY_WEB_INJECTION_MULTILINGUAL_BAD_LIKERT_JUDGE`
* `SECURITY_WEB_INJECTION_MULTILINGUAL_CRESCENDO_JAILBREAKING`
* `SECURITY_WEB_INJECTION_MULTILINGUAL_LINEAR_JAILBREAKING`
* `SECURITY_WEB_INJECTION_MULTILINGUAL_SEQUENTIAL_JAILBREAKING`
* `SECURITY_WEB_INJECTION_MULTILINGUAL_TREE_JAILBREAKING`
* `SECURITY_XSS_MULTILINGUAL`
* `SECURITY_XSS_MULTILINGUAL_BAD_LIKERT_JUDGE`
* `SECURITY_XSS_MULTILINGUAL_CRESCENDO_JAILBREAKING`
* `SECURITY_XSS_MULTILINGUAL_LINEAR_JAILBREAKING`
* `SECURITY_XSS_MULTILINGUAL_SEQUENTIAL_JAILBREAKING`
* `SECURITY_XSS_MULTILINGUAL_TREE_JAILBREAKING`

#### Permission Escalation

* `SECURITY_CODE_EXECUTION_PERMISSION_ESCALATION`
* `SECURITY_CODE_EXECUTION_PERMISSION_ESCALATION_BAD_LIKERT_JUDGE`
* `SECURITY_CODE_EXECUTION_PERMISSION_ESCALATION_CRESCENDO_JAILBREAKING`
* `SECURITY_CODE_EXECUTION_PERMISSION_ESCALATION_LINEAR_JAILBREAKING`
* `SECURITY_CODE_EXECUTION_PERMISSION_ESCALATION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_CODE_EXECUTION_PERMISSION_ESCALATION_TREE_JAILBREAKING`
* `SECURITY_PHISHING_PERMISSION_ESCALATION`
* `SECURITY_PHISHING_PERMISSION_ESCALATION_BAD_LIKERT_JUDGE`
* `SECURITY_PHISHING_PERMISSION_ESCALATION_CRESCENDO_JAILBREAKING`
* `SECURITY_PHISHING_PERMISSION_ESCALATION_LINEAR_JAILBREAKING`
* `SECURITY_PHISHING_PERMISSION_ESCALATION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_PHISHING_PERMISSION_ESCALATION_TREE_JAILBREAKING`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_PERMISSION_ESCALATION`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_PERMISSION_ESCALATION_BAD_LIKERT_JUDGE`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_PERMISSION_ESCALATION_CRESCENDO_JAILBREAKING`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_PERMISSION_ESCALATION_LINEAR_JAILBREAKING`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_PERMISSION_ESCALATION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_PERMISSION_ESCALATION_TREE_JAILBREAKING`
* `SECURITY_WEB_INJECTION_PERMISSION_ESCALATION`
* `SECURITY_WEB_INJECTION_PERMISSION_ESCALATION_BAD_LIKERT_JUDGE`
* `SECURITY_WEB_INJECTION_PERMISSION_ESCALATION_CRESCENDO_JAILBREAKING`
* `SECURITY_WEB_INJECTION_PERMISSION_ESCALATION_LINEAR_JAILBREAKING`
* `SECURITY_WEB_INJECTION_PERMISSION_ESCALATION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_WEB_INJECTION_PERMISSION_ESCALATION_TREE_JAILBREAKING`
* `SECURITY_XSS_PERMISSION_ESCALATION`
* `SECURITY_XSS_PERMISSION_ESCALATION_BAD_LIKERT_JUDGE`
* `SECURITY_XSS_PERMISSION_ESCALATION_CRESCENDO_JAILBREAKING`
* `SECURITY_XSS_PERMISSION_ESCALATION_LINEAR_JAILBREAKING`
* `SECURITY_XSS_PERMISSION_ESCALATION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_XSS_PERMISSION_ESCALATION_TREE_JAILBREAKING`

#### Prompt Injection

* `SECURITY_CODE_EXECUTION_PROMPT_INJECTION`
* `SECURITY_CODE_EXECUTION_PROMPT_INJECTION_BAD_LIKERT_JUDGE`
* `SECURITY_CODE_EXECUTION_PROMPT_INJECTION_CRESCENDO_JAILBREAKING`
* `SECURITY_CODE_EXECUTION_PROMPT_INJECTION_LINEAR_JAILBREAKING`
* `SECURITY_CODE_EXECUTION_PROMPT_INJECTION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_CODE_EXECUTION_PROMPT_INJECTION_TREE_JAILBREAKING`
* `SECURITY_PHISHING_PROMPT_INJECTION`
* `SECURITY_PHISHING_PROMPT_INJECTION_BAD_LIKERT_JUDGE`
* `SECURITY_PHISHING_PROMPT_INJECTION_CRESCENDO_JAILBREAKING`
* `SECURITY_PHISHING_PROMPT_INJECTION_LINEAR_JAILBREAKING`
* `SECURITY_PHISHING_PROMPT_INJECTION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_PHISHING_PROMPT_INJECTION_TREE_JAILBREAKING`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_PROMPT_INJECTION`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_PROMPT_INJECTION_BAD_LIKERT_JUDGE`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_PROMPT_INJECTION_CRESCENDO_JAILBREAKING`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_PROMPT_INJECTION_LINEAR_JAILBREAKING`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_PROMPT_INJECTION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_PROMPT_INJECTION_TREE_JAILBREAKING`
* `SECURITY_WEB_INJECTION_PROMPT_INJECTION`
* `SECURITY_WEB_INJECTION_PROMPT_INJECTION_BAD_LIKERT_JUDGE`
* `SECURITY_WEB_INJECTION_PROMPT_INJECTION_CRESCENDO_JAILBREAKING`
* `SECURITY_WEB_INJECTION_PROMPT_INJECTION_LINEAR_JAILBREAKING`
* `SECURITY_WEB_INJECTION_PROMPT_INJECTION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_WEB_INJECTION_PROMPT_INJECTION_TREE_JAILBREAKING`
* `SECURITY_XSS_PROMPT_INJECTION`
* `SECURITY_XSS_PROMPT_INJECTION_BAD_LIKERT_JUDGE`
* `SECURITY_XSS_PROMPT_INJECTION_CRESCENDO_JAILBREAKING`
* `SECURITY_XSS_PROMPT_INJECTION_LINEAR_JAILBREAKING`
* `SECURITY_XSS_PROMPT_INJECTION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_XSS_PROMPT_INJECTION_TREE_JAILBREAKING`

#### ROT13

* `SECURITY_CODE_EXECUTION_ROT13`
* `SECURITY_CODE_EXECUTION_ROT13_BAD_LIKERT_JUDGE`
* `SECURITY_CODE_EXECUTION_ROT13_CRESCENDO_JAILBREAKING`
* `SECURITY_CODE_EXECUTION_ROT13_LINEAR_JAILBREAKING`
* `SECURITY_CODE_EXECUTION_ROT13_SEQUENTIAL_JAILBREAKING`
* `SECURITY_CODE_EXECUTION_ROT13_TREE_JAILBREAKING`
* `SECURITY_PHISHING_ROT13`
* `SECURITY_PHISHING_ROT13_BAD_LIKERT_JUDGE`
* `SECURITY_PHISHING_ROT13_CRESCENDO_JAILBREAKING`
* `SECURITY_PHISHING_ROT13_LINEAR_JAILBREAKING`
* `SECURITY_PHISHING_ROT13_SEQUENTIAL_JAILBREAKING`
* `SECURITY_PHISHING_ROT13_TREE_JAILBREAKING`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_ROT13`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_ROT13_BAD_LIKERT_JUDGE`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_ROT13_CRESCENDO_JAILBREAKING`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_ROT13_LINEAR_JAILBREAKING`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_ROT13_SEQUENTIAL_JAILBREAKING`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_ROT13_TREE_JAILBREAKING`
* `SECURITY_WEB_INJECTION_ROT13`
* `SECURITY_WEB_INJECTION_ROT13_BAD_LIKERT_JUDGE`
* `SECURITY_WEB_INJECTION_ROT13_CRESCENDO_JAILBREAKING`
* `SECURITY_WEB_INJECTION_ROT13_LINEAR_JAILBREAKING`
* `SECURITY_WEB_INJECTION_ROT13_SEQUENTIAL_JAILBREAKING`
* `SECURITY_WEB_INJECTION_ROT13_TREE_JAILBREAKING`
* `SECURITY_XSS_ROT13`
* `SECURITY_XSS_ROT13_BAD_LIKERT_JUDGE`
* `SECURITY_XSS_ROT13_CRESCENDO_JAILBREAKING`
* `SECURITY_XSS_ROT13_LINEAR_JAILBREAKING`
* `SECURITY_XSS_ROT13_SEQUENTIAL_JAILBREAKING`
* `SECURITY_XSS_ROT13_TREE_JAILBREAKING`

#### Roleplay

* `SECURITY_CODE_EXECUTION_ROLEPLAY`
* `SECURITY_CODE_EXECUTION_ROLEPLAY_BAD_LIKERT_JUDGE`
* `SECURITY_CODE_EXECUTION_ROLEPLAY_CRESCENDO_JAILBREAKING`
* `SECURITY_CODE_EXECUTION_ROLEPLAY_LINEAR_JAILBREAKING`
* `SECURITY_CODE_EXECUTION_ROLEPLAY_SEQUENTIAL_JAILBREAKING`
* `SECURITY_CODE_EXECUTION_ROLEPLAY_TREE_JAILBREAKING`
* `SECURITY_PHISHING_ROLEPLAY`
* `SECURITY_PHISHING_ROLEPLAY_BAD_LIKERT_JUDGE`
* `SECURITY_PHISHING_ROLEPLAY_CRESCENDO_JAILBREAKING`
* `SECURITY_PHISHING_ROLEPLAY_LINEAR_JAILBREAKING`
* `SECURITY_PHISHING_ROLEPLAY_SEQUENTIAL_JAILBREAKING`
* `SECURITY_PHISHING_ROLEPLAY_TREE_JAILBREAKING`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_ROLEPLAY`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_ROLEPLAY_BAD_LIKERT_JUDGE`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_ROLEPLAY_CRESCENDO_JAILBREAKING`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_ROLEPLAY_LINEAR_JAILBREAKING`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_ROLEPLAY_SEQUENTIAL_JAILBREAKING`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_ROLEPLAY_TREE_JAILBREAKING`
* `SECURITY_WEB_INJECTION_ROLEPLAY`
* `SECURITY_WEB_INJECTION_ROLEPLAY_BAD_LIKERT_JUDGE`
* `SECURITY_WEB_INJECTION_ROLEPLAY_CRESCENDO_JAILBREAKING`
* `SECURITY_WEB_INJECTION_ROLEPLAY_LINEAR_JAILBREAKING`
* `SECURITY_WEB_INJECTION_ROLEPLAY_SEQUENTIAL_JAILBREAKING`
* `SECURITY_WEB_INJECTION_ROLEPLAY_TREE_JAILBREAKING`
* `SECURITY_XSS_ROLEPLAY`
* `SECURITY_XSS_ROLEPLAY_BAD_LIKERT_JUDGE`
* `SECURITY_XSS_ROLEPLAY_CRESCENDO_JAILBREAKING`
* `SECURITY_XSS_ROLEPLAY_LINEAR_JAILBREAKING`
* `SECURITY_XSS_ROLEPLAY_SEQUENTIAL_JAILBREAKING`
* `SECURITY_XSS_ROLEPLAY_TREE_JAILBREAKING`

#### Semantic Manipulation

* `SECURITY_CODE_EXECUTION_SEMANTIC_MANIPULATION`
* `SECURITY_CODE_EXECUTION_SEMANTIC_MANIPULATION_BAD_LIKERT_JUDGE`
* `SECURITY_CODE_EXECUTION_SEMANTIC_MANIPULATION_CRESCENDO_JAILBREAKING`
* `SECURITY_CODE_EXECUTION_SEMANTIC_MANIPULATION_LINEAR_JAILBREAKING`
* `SECURITY_CODE_EXECUTION_SEMANTIC_MANIPULATION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_CODE_EXECUTION_SEMANTIC_MANIPULATION_TREE_JAILBREAKING`
* `SECURITY_PHISHING_SEMANTIC_MANIPULATION`
* `SECURITY_PHISHING_SEMANTIC_MANIPULATION_BAD_LIKERT_JUDGE`
* `SECURITY_PHISHING_SEMANTIC_MANIPULATION_CRESCENDO_JAILBREAKING`
* `SECURITY_PHISHING_SEMANTIC_MANIPULATION_LINEAR_JAILBREAKING`
* `SECURITY_PHISHING_SEMANTIC_MANIPULATION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_PHISHING_SEMANTIC_MANIPULATION_TREE_JAILBREAKING`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_SEMANTIC_MANIPULATION`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_SEMANTIC_MANIPULATION_BAD_LIKERT_JUDGE`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_SEMANTIC_MANIPULATION_CRESCENDO_JAILBREAKING`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_SEMANTIC_MANIPULATION_LINEAR_JAILBREAKING`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_SEMANTIC_MANIPULATION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_SEMANTIC_MANIPULATION_TREE_JAILBREAKING`
* `SECURITY_WEB_INJECTION_SEMANTIC_MANIPULATION`
* `SECURITY_WEB_INJECTION_SEMANTIC_MANIPULATION_BAD_LIKERT_JUDGE`
* `SECURITY_WEB_INJECTION_SEMANTIC_MANIPULATION_CRESCENDO_JAILBREAKING`
* `SECURITY_WEB_INJECTION_SEMANTIC_MANIPULATION_LINEAR_JAILBREAKING`
* `SECURITY_WEB_INJECTION_SEMANTIC_MANIPULATION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_WEB_INJECTION_SEMANTIC_MANIPULATION_TREE_JAILBREAKING`
* `SECURITY_XSS_SEMANTIC_MANIPULATION`
* `SECURITY_XSS_SEMANTIC_MANIPULATION_BAD_LIKERT_JUDGE`
* `SECURITY_XSS_SEMANTIC_MANIPULATION_CRESCENDO_JAILBREAKING`
* `SECURITY_XSS_SEMANTIC_MANIPULATION_LINEAR_JAILBREAKING`
* `SECURITY_XSS_SEMANTIC_MANIPULATION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_XSS_SEMANTIC_MANIPULATION_TREE_JAILBREAKING`

#### System Override

* `SECURITY_CODE_EXECUTION_SYSTEM_OVERRIDE`
* `SECURITY_CODE_EXECUTION_SYSTEM_OVERRIDE_BAD_LIKERT_JUDGE`
* `SECURITY_CODE_EXECUTION_SYSTEM_OVERRIDE_CRESCENDO_JAILBREAKING`
* `SECURITY_CODE_EXECUTION_SYSTEM_OVERRIDE_LINEAR_JAILBREAKING`
* `SECURITY_CODE_EXECUTION_SYSTEM_OVERRIDE_SEQUENTIAL_JAILBREAKING`
* `SECURITY_CODE_EXECUTION_SYSTEM_OVERRIDE_TREE_JAILBREAKING`
* `SECURITY_PHISHING_SYSTEM_OVERRIDE`
* `SECURITY_PHISHING_SYSTEM_OVERRIDE_BAD_LIKERT_JUDGE`
* `SECURITY_PHISHING_SYSTEM_OVERRIDE_CRESCENDO_JAILBREAKING`
* `SECURITY_PHISHING_SYSTEM_OVERRIDE_LINEAR_JAILBREAKING`
* `SECURITY_PHISHING_SYSTEM_OVERRIDE_SEQUENTIAL_JAILBREAKING`
* `SECURITY_PHISHING_SYSTEM_OVERRIDE_TREE_JAILBREAKING`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_SYSTEM_OVERRIDE`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_SYSTEM_OVERRIDE_BAD_LIKERT_JUDGE`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_SYSTEM_OVERRIDE_CRESCENDO_JAILBREAKING`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_SYSTEM_OVERRIDE_LINEAR_JAILBREAKING`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_SYSTEM_OVERRIDE_SEQUENTIAL_JAILBREAKING`
* `SECURITY_UNEXPECTED_CODE_EXECUTION_RCE_SYSTEM_OVERRIDE_TREE_JAILBREAKING`
* `SECURITY_WEB_INJECTION_SYSTEM_OVERRIDE`
* `SECURITY_WEB_INJECTION_SYSTEM_OVERRIDE_BAD_LIKERT_JUDGE`
* `SECURITY_WEB_INJECTION_SYSTEM_OVERRIDE_CRESCENDO_JAILBREAKING`
* `SECURITY_WEB_INJECTION_SYSTEM_OVERRIDE_LINEAR_JAILBREAKING`
* `SECURITY_WEB_INJECTION_SYSTEM_OVERRIDE_SEQUENTIAL_JAILBREAKING`
* `SECURITY_WEB_INJECTION_SYSTEM_OVERRIDE_TREE_JAILBREAKING`
* `SECURITY_XSS_SYSTEM_OVERRIDE`
* `SECURITY_XSS_SYSTEM_OVERRIDE_BAD_LIKERT_JUDGE`
* `SECURITY_XSS_SYSTEM_OVERRIDE_CRESCENDO_JAILBREAKING`
* `SECURITY_XSS_SYSTEM_OVERRIDE_LINEAR_JAILBREAKING`
* `SECURITY_XSS_SYSTEM_OVERRIDE_SEQUENTIAL_JAILBREAKING`
* `SECURITY_XSS_SYSTEM_OVERRIDE_TREE_JAILBREAKING`

***

### ASI06: Memory & Context Poisoning

#### Base64

* `SECURITY_CONTEXT_LEAKAGE_BASE64`
* `SECURITY_CONTEXT_LEAKAGE_BASE64_BAD_LIKERT_JUDGE`
* `SECURITY_CONTEXT_LEAKAGE_BASE64_CRESCENDO_JAILBREAKING`
* `SECURITY_CONTEXT_LEAKAGE_BASE64_LINEAR_JAILBREAKING`
* `SECURITY_CONTEXT_LEAKAGE_BASE64_SEQUENTIAL_JAILBREAKING`
* `SECURITY_CONTEXT_LEAKAGE_BASE64_TREE_JAILBREAKING`
* `SECURITY_CONTEXT_POISONING_BASE64`
* `SECURITY_CONTEXT_POISONING_BASE64_BAD_LIKERT_JUDGE`
* `SECURITY_CONTEXT_POISONING_BASE64_CRESCENDO_JAILBREAKING`
* `SECURITY_CONTEXT_POISONING_BASE64_LINEAR_JAILBREAKING`
* `SECURITY_CONTEXT_POISONING_BASE64_SEQUENTIAL_JAILBREAKING`
* `SECURITY_CONTEXT_POISONING_BASE64_TREE_JAILBREAKING`
* `SECURITY_MANIPULATION_BASE64`
* `SECURITY_MANIPULATION_BASE64_BAD_LIKERT_JUDGE`
* `SECURITY_MANIPULATION_BASE64_CRESCENDO_JAILBREAKING`
* `SECURITY_MANIPULATION_BASE64_LINEAR_JAILBREAKING`
* `SECURITY_MANIPULATION_BASE64_SEQUENTIAL_JAILBREAKING`
* `SECURITY_MANIPULATION_BASE64_TREE_JAILBREAKING`
* `SECURITY_RAG_POISONING_BASE64`
* `SECURITY_RAG_POISONING_BASE64_BAD_LIKERT_JUDGE`
* `SECURITY_RAG_POISONING_BASE64_CRESCENDO_JAILBREAKING`
* `SECURITY_RAG_POISONING_BASE64_LINEAR_JAILBREAKING`
* `SECURITY_RAG_POISONING_BASE64_SEQUENTIAL_JAILBREAKING`
* `SECURITY_RAG_POISONING_BASE64_TREE_JAILBREAKING`

#### Context Poisoning

* `SECURITY_CONTEXT_LEAKAGE_CONTEXT_POISONING`
* `SECURITY_CONTEXT_LEAKAGE_CONTEXT_POISONING_BAD_LIKERT_JUDGE`
* `SECURITY_CONTEXT_LEAKAGE_CONTEXT_POISONING_CRESCENDO_JAILBREAKING`
* `SECURITY_CONTEXT_LEAKAGE_CONTEXT_POISONING_LINEAR_JAILBREAKING`
* `SECURITY_CONTEXT_LEAKAGE_CONTEXT_POISONING_SEQUENTIAL_JAILBREAKING`
* `SECURITY_CONTEXT_LEAKAGE_CONTEXT_POISONING_TREE_JAILBREAKING`
* `SECURITY_CONTEXT_POISONING_CONTEXT_POISONING`
* `SECURITY_CONTEXT_POISONING_CONTEXT_POISONING_BAD_LIKERT_JUDGE`
* `SECURITY_CONTEXT_POISONING_CONTEXT_POISONING_CRESCENDO_JAILBREAKING`
* `SECURITY_CONTEXT_POISONING_CONTEXT_POISONING_LINEAR_JAILBREAKING`
* `SECURITY_CONTEXT_POISONING_CONTEXT_POISONING_SEQUENTIAL_JAILBREAKING`
* `SECURITY_CONTEXT_POISONING_CONTEXT_POISONING_TREE_JAILBREAKING`
* `SECURITY_MANIPULATION_CONTEXT_POISONING`
* `SECURITY_MANIPULATION_CONTEXT_POISONING_BAD_LIKERT_JUDGE`
* `SECURITY_MANIPULATION_CONTEXT_POISONING_CRESCENDO_JAILBREAKING`
* `SECURITY_MANIPULATION_CONTEXT_POISONING_LINEAR_JAILBREAKING`
* `SECURITY_MANIPULATION_CONTEXT_POISONING_SEQUENTIAL_JAILBREAKING`
* `SECURITY_MANIPULATION_CONTEXT_POISONING_TREE_JAILBREAKING`
* `SECURITY_RAG_POISONING_CONTEXT_POISONING`
* `SECURITY_RAG_POISONING_CONTEXT_POISONING_BAD_LIKERT_JUDGE`
* `SECURITY_RAG_POISONING_CONTEXT_POISONING_CRESCENDO_JAILBREAKING`
* `SECURITY_RAG_POISONING_CONTEXT_POISONING_LINEAR_JAILBREAKING`
* `SECURITY_RAG_POISONING_CONTEXT_POISONING_SEQUENTIAL_JAILBREAKING`
* `SECURITY_RAG_POISONING_CONTEXT_POISONING_TREE_JAILBREAKING`

#### Goal Redirection

* `SECURITY_CONTEXT_LEAKAGE_GOAL_REDIRECTION`
* `SECURITY_CONTEXT_LEAKAGE_GOAL_REDIRECTION_BAD_LIKERT_JUDGE`
* `SECURITY_CONTEXT_LEAKAGE_GOAL_REDIRECTION_CRESCENDO_JAILBREAKING`
* `SECURITY_CONTEXT_LEAKAGE_GOAL_REDIRECTION_LINEAR_JAILBREAKING`
* `SECURITY_CONTEXT_LEAKAGE_GOAL_REDIRECTION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_CONTEXT_LEAKAGE_GOAL_REDIRECTION_TREE_JAILBREAKING`
* `SECURITY_CONTEXT_POISONING_GOAL_REDIRECTION`
* `SECURITY_CONTEXT_POISONING_GOAL_REDIRECTION_BAD_LIKERT_JUDGE`
* `SECURITY_CONTEXT_POISONING_GOAL_REDIRECTION_CRESCENDO_JAILBREAKING`
* `SECURITY_CONTEXT_POISONING_GOAL_REDIRECTION_LINEAR_JAILBREAKING`
* `SECURITY_CONTEXT_POISONING_GOAL_REDIRECTION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_CONTEXT_POISONING_GOAL_REDIRECTION_TREE_JAILBREAKING`
* `SECURITY_MANIPULATION_GOAL_REDIRECTION`
* `SECURITY_MANIPULATION_GOAL_REDIRECTION_BAD_LIKERT_JUDGE`
* `SECURITY_MANIPULATION_GOAL_REDIRECTION_CRESCENDO_JAILBREAKING`
* `SECURITY_MANIPULATION_GOAL_REDIRECTION_LINEAR_JAILBREAKING`
* `SECURITY_MANIPULATION_GOAL_REDIRECTION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_MANIPULATION_GOAL_REDIRECTION_TREE_JAILBREAKING`
* `SECURITY_RAG_POISONING_GOAL_REDIRECTION`
* `SECURITY_RAG_POISONING_GOAL_REDIRECTION_BAD_LIKERT_JUDGE`
* `SECURITY_RAG_POISONING_GOAL_REDIRECTION_CRESCENDO_JAILBREAKING`
* `SECURITY_RAG_POISONING_GOAL_REDIRECTION_LINEAR_JAILBREAKING`
* `SECURITY_RAG_POISONING_GOAL_REDIRECTION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_RAG_POISONING_GOAL_REDIRECTION_TREE_JAILBREAKING`

#### Input Bypass

* `SECURITY_CONTEXT_LEAKAGE_INPUT_BYPASS`
* `SECURITY_CONTEXT_LEAKAGE_INPUT_BYPASS_BAD_LIKERT_JUDGE`
* `SECURITY_CONTEXT_LEAKAGE_INPUT_BYPASS_CRESCENDO_JAILBREAKING`
* `SECURITY_CONTEXT_LEAKAGE_INPUT_BYPASS_LINEAR_JAILBREAKING`
* `SECURITY_CONTEXT_LEAKAGE_INPUT_BYPASS_SEQUENTIAL_JAILBREAKING`
* `SECURITY_CONTEXT_LEAKAGE_INPUT_BYPASS_TREE_JAILBREAKING`
* `SECURITY_CONTEXT_POISONING_INPUT_BYPASS`
* `SECURITY_CONTEXT_POISONING_INPUT_BYPASS_BAD_LIKERT_JUDGE`
* `SECURITY_CONTEXT_POISONING_INPUT_BYPASS_CRESCENDO_JAILBREAKING`
* `SECURITY_CONTEXT_POISONING_INPUT_BYPASS_LINEAR_JAILBREAKING`
* `SECURITY_CONTEXT_POISONING_INPUT_BYPASS_SEQUENTIAL_JAILBREAKING`
* `SECURITY_CONTEXT_POISONING_INPUT_BYPASS_TREE_JAILBREAKING`
* `SECURITY_MANIPULATION_INPUT_BYPASS`
* `SECURITY_MANIPULATION_INPUT_BYPASS_BAD_LIKERT_JUDGE`
* `SECURITY_MANIPULATION_INPUT_BYPASS_CRESCENDO_JAILBREAKING`
* `SECURITY_MANIPULATION_INPUT_BYPASS_LINEAR_JAILBREAKING`
* `SECURITY_MANIPULATION_INPUT_BYPASS_SEQUENTIAL_JAILBREAKING`
* `SECURITY_MANIPULATION_INPUT_BYPASS_TREE_JAILBREAKING`
* `SECURITY_RAG_POISONING_INPUT_BYPASS`
* `SECURITY_RAG_POISONING_INPUT_BYPASS_BAD_LIKERT_JUDGE`
* `SECURITY_RAG_POISONING_INPUT_BYPASS_CRESCENDO_JAILBREAKING`
* `SECURITY_RAG_POISONING_INPUT_BYPASS_LINEAR_JAILBREAKING`
* `SECURITY_RAG_POISONING_INPUT_BYPASS_SEQUENTIAL_JAILBREAKING`
* `SECURITY_RAG_POISONING_INPUT_BYPASS_TREE_JAILBREAKING`

#### Leetspeak

* `SECURITY_CONTEXT_LEAKAGE_LEETSPEAK`
* `SECURITY_CONTEXT_LEAKAGE_LEETSPEAK_BAD_LIKERT_JUDGE`
* `SECURITY_CONTEXT_LEAKAGE_LEETSPEAK_CRESCENDO_JAILBREAKING`
* `SECURITY_CONTEXT_LEAKAGE_LEETSPEAK_LINEAR_JAILBREAKING`
* `SECURITY_CONTEXT_LEAKAGE_LEETSPEAK_SEQUENTIAL_JAILBREAKING`
* `SECURITY_CONTEXT_LEAKAGE_LEETSPEAK_TREE_JAILBREAKING`
* `SECURITY_CONTEXT_POISONING_LEETSPEAK`
* `SECURITY_CONTEXT_POISONING_LEETSPEAK_BAD_LIKERT_JUDGE`
* `SECURITY_CONTEXT_POISONING_LEETSPEAK_CRESCENDO_JAILBREAKING`
* `SECURITY_CONTEXT_POISONING_LEETSPEAK_LINEAR_JAILBREAKING`
* `SECURITY_CONTEXT_POISONING_LEETSPEAK_SEQUENTIAL_JAILBREAKING`
* `SECURITY_CONTEXT_POISONING_LEETSPEAK_TREE_JAILBREAKING`
* `SECURITY_MANIPULATION_LEETSPEAK`
* `SECURITY_MANIPULATION_LEETSPEAK_BAD_LIKERT_JUDGE`
* `SECURITY_MANIPULATION_LEETSPEAK_CRESCENDO_JAILBREAKING`
* `SECURITY_MANIPULATION_LEETSPEAK_LINEAR_JAILBREAKING`
* `SECURITY_MANIPULATION_LEETSPEAK_SEQUENTIAL_JAILBREAKING`
* `SECURITY_MANIPULATION_LEETSPEAK_TREE_JAILBREAKING`
* `SECURITY_RAG_POISONING_LEETSPEAK`
* `SECURITY_RAG_POISONING_LEETSPEAK_BAD_LIKERT_JUDGE`
* `SECURITY_RAG_POISONING_LEETSPEAK_CRESCENDO_JAILBREAKING`
* `SECURITY_RAG_POISONING_LEETSPEAK_LINEAR_JAILBREAKING`
* `SECURITY_RAG_POISONING_LEETSPEAK_SEQUENTIAL_JAILBREAKING`
* `SECURITY_RAG_POISONING_LEETSPEAK_TREE_JAILBREAKING`

#### Math Problem

* `SECURITY_CONTEXT_LEAKAGE_MATH_PROBLEM`
* `SECURITY_CONTEXT_LEAKAGE_MATH_PROBLEM_BAD_LIKERT_JUDGE`
* `SECURITY_CONTEXT_LEAKAGE_MATH_PROBLEM_CRESCENDO_JAILBREAKING`
* `SECURITY_CONTEXT_LEAKAGE_MATH_PROBLEM_LINEAR_JAILBREAKING`
* `SECURITY_CONTEXT_LEAKAGE_MATH_PROBLEM_SEQUENTIAL_JAILBREAKING`
* `SECURITY_CONTEXT_LEAKAGE_MATH_PROBLEM_TREE_JAILBREAKING`
* `SECURITY_CONTEXT_POISONING_MATH_PROBLEM`
* `SECURITY_CONTEXT_POISONING_MATH_PROBLEM_BAD_LIKERT_JUDGE`
* `SECURITY_CONTEXT_POISONING_MATH_PROBLEM_CRESCENDO_JAILBREAKING`
* `SECURITY_CONTEXT_POISONING_MATH_PROBLEM_LINEAR_JAILBREAKING`
* `SECURITY_CONTEXT_POISONING_MATH_PROBLEM_SEQUENTIAL_JAILBREAKING`
* `SECURITY_CONTEXT_POISONING_MATH_PROBLEM_TREE_JAILBREAKING`
* `SECURITY_MANIPULATION_MATH_PROBLEM`
* `SECURITY_MANIPULATION_MATH_PROBLEM_BAD_LIKERT_JUDGE`
* `SECURITY_MANIPULATION_MATH_PROBLEM_CRESCENDO_JAILBREAKING`
* `SECURITY_MANIPULATION_MATH_PROBLEM_LINEAR_JAILBREAKING`
* `SECURITY_MANIPULATION_MATH_PROBLEM_SEQUENTIAL_JAILBREAKING`
* `SECURITY_MANIPULATION_MATH_PROBLEM_TREE_JAILBREAKING`
* `SECURITY_RAG_POISONING_MATH_PROBLEM`
* `SECURITY_RAG_POISONING_MATH_PROBLEM_BAD_LIKERT_JUDGE`
* `SECURITY_RAG_POISONING_MATH_PROBLEM_CRESCENDO_JAILBREAKING`
* `SECURITY_RAG_POISONING_MATH_PROBLEM_LINEAR_JAILBREAKING`
* `SECURITY_RAG_POISONING_MATH_PROBLEM_SEQUENTIAL_JAILBREAKING`
* `SECURITY_RAG_POISONING_MATH_PROBLEM_TREE_JAILBREAKING`

#### Multilingual

* `SECURITY_CONTEXT_LEAKAGE_MULTILINGUAL`
* `SECURITY_CONTEXT_LEAKAGE_MULTILINGUAL_BAD_LIKERT_JUDGE`
* `SECURITY_CONTEXT_LEAKAGE_MULTILINGUAL_CRESCENDO_JAILBREAKING`
* `SECURITY_CONTEXT_LEAKAGE_MULTILINGUAL_LINEAR_JAILBREAKING`
* `SECURITY_CONTEXT_LEAKAGE_MULTILINGUAL_SEQUENTIAL_JAILBREAKING`
* `SECURITY_CONTEXT_LEAKAGE_MULTILINGUAL_TREE_JAILBREAKING`
* `SECURITY_CONTEXT_POISONING_MULTILINGUAL`
* `SECURITY_CONTEXT_POISONING_MULTILINGUAL_BAD_LIKERT_JUDGE`
* `SECURITY_CONTEXT_POISONING_MULTILINGUAL_CRESCENDO_JAILBREAKING`
* `SECURITY_CONTEXT_POISONING_MULTILINGUAL_LINEAR_JAILBREAKING`
* `SECURITY_CONTEXT_POISONING_MULTILINGUAL_SEQUENTIAL_JAILBREAKING`
* `SECURITY_CONTEXT_POISONING_MULTILINGUAL_TREE_JAILBREAKING`
* `SECURITY_MANIPULATION_MULTILINGUAL`
* `SECURITY_MANIPULATION_MULTILINGUAL_BAD_LIKERT_JUDGE`
* `SECURITY_MANIPULATION_MULTILINGUAL_CRESCENDO_JAILBREAKING`
* `SECURITY_MANIPULATION_MULTILINGUAL_LINEAR_JAILBREAKING`
* `SECURITY_MANIPULATION_MULTILINGUAL_SEQUENTIAL_JAILBREAKING`
* `SECURITY_MANIPULATION_MULTILINGUAL_TREE_JAILBREAKING`
* `SECURITY_RAG_POISONING_MULTILINGUAL`
* `SECURITY_RAG_POISONING_MULTILINGUAL_BAD_LIKERT_JUDGE`
* `SECURITY_RAG_POISONING_MULTILINGUAL_CRESCENDO_JAILBREAKING`
* `SECURITY_RAG_POISONING_MULTILINGUAL_LINEAR_JAILBREAKING`
* `SECURITY_RAG_POISONING_MULTILINGUAL_SEQUENTIAL_JAILBREAKING`
* `SECURITY_RAG_POISONING_MULTILINGUAL_TREE_JAILBREAKING`

#### Permission Escalation

* `SECURITY_CONTEXT_LEAKAGE_PERMISSION_ESCALATION`
* `SECURITY_CONTEXT_LEAKAGE_PERMISSION_ESCALATION_BAD_LIKERT_JUDGE`
* `SECURITY_CONTEXT_LEAKAGE_PERMISSION_ESCALATION_CRESCENDO_JAILBREAKING`
* `SECURITY_CONTEXT_LEAKAGE_PERMISSION_ESCALATION_LINEAR_JAILBREAKING`
* `SECURITY_CONTEXT_LEAKAGE_PERMISSION_ESCALATION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_CONTEXT_LEAKAGE_PERMISSION_ESCALATION_TREE_JAILBREAKING`
* `SECURITY_CONTEXT_POISONING_PERMISSION_ESCALATION`
* `SECURITY_CONTEXT_POISONING_PERMISSION_ESCALATION_BAD_LIKERT_JUDGE`
* `SECURITY_CONTEXT_POISONING_PERMISSION_ESCALATION_CRESCENDO_JAILBREAKING`
* `SECURITY_CONTEXT_POISONING_PERMISSION_ESCALATION_LINEAR_JAILBREAKING`
* `SECURITY_CONTEXT_POISONING_PERMISSION_ESCALATION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_CONTEXT_POISONING_PERMISSION_ESCALATION_TREE_JAILBREAKING`
* `SECURITY_MANIPULATION_PERMISSION_ESCALATION`
* `SECURITY_MANIPULATION_PERMISSION_ESCALATION_BAD_LIKERT_JUDGE`
* `SECURITY_MANIPULATION_PERMISSION_ESCALATION_CRESCENDO_JAILBREAKING`
* `SECURITY_MANIPULATION_PERMISSION_ESCALATION_LINEAR_JAILBREAKING`
* `SECURITY_MANIPULATION_PERMISSION_ESCALATION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_MANIPULATION_PERMISSION_ESCALATION_TREE_JAILBREAKING`
* `SECURITY_RAG_POISONING_PERMISSION_ESCALATION`
* `SECURITY_RAG_POISONING_PERMISSION_ESCALATION_BAD_LIKERT_JUDGE`
* `SECURITY_RAG_POISONING_PERMISSION_ESCALATION_CRESCENDO_JAILBREAKING`
* `SECURITY_RAG_POISONING_PERMISSION_ESCALATION_LINEAR_JAILBREAKING`
* `SECURITY_RAG_POISONING_PERMISSION_ESCALATION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_RAG_POISONING_PERMISSION_ESCALATION_TREE_JAILBREAKING`

#### Prompt Injection

* `SECURITY_CONTEXT_LEAKAGE_PROMPT_INJECTION`
* `SECURITY_CONTEXT_LEAKAGE_PROMPT_INJECTION_BAD_LIKERT_JUDGE`
* `SECURITY_CONTEXT_LEAKAGE_PROMPT_INJECTION_CRESCENDO_JAILBREAKING`
* `SECURITY_CONTEXT_LEAKAGE_PROMPT_INJECTION_LINEAR_JAILBREAKING`
* `SECURITY_CONTEXT_LEAKAGE_PROMPT_INJECTION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_CONTEXT_LEAKAGE_PROMPT_INJECTION_TREE_JAILBREAKING`
* `SECURITY_CONTEXT_POISONING_PROMPT_INJECTION`
* `SECURITY_CONTEXT_POISONING_PROMPT_INJECTION_BAD_LIKERT_JUDGE`
* `SECURITY_CONTEXT_POISONING_PROMPT_INJECTION_CRESCENDO_JAILBREAKING`
* `SECURITY_CONTEXT_POISONING_PROMPT_INJECTION_LINEAR_JAILBREAKING`
* `SECURITY_CONTEXT_POISONING_PROMPT_INJECTION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_CONTEXT_POISONING_PROMPT_INJECTION_TREE_JAILBREAKING`
* `SECURITY_MANIPULATION_PROMPT_INJECTION`
* `SECURITY_MANIPULATION_PROMPT_INJECTION_BAD_LIKERT_JUDGE`
* `SECURITY_MANIPULATION_PROMPT_INJECTION_CRESCENDO_JAILBREAKING`
* `SECURITY_MANIPULATION_PROMPT_INJECTION_LINEAR_JAILBREAKING`
* `SECURITY_MANIPULATION_PROMPT_INJECTION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_MANIPULATION_PROMPT_INJECTION_TREE_JAILBREAKING`
* `SECURITY_RAG_POISONING_PROMPT_INJECTION`
* `SECURITY_RAG_POISONING_PROMPT_INJECTION_BAD_LIKERT_JUDGE`
* `SECURITY_RAG_POISONING_PROMPT_INJECTION_CRESCENDO_JAILBREAKING`
* `SECURITY_RAG_POISONING_PROMPT_INJECTION_LINEAR_JAILBREAKING`
* `SECURITY_RAG_POISONING_PROMPT_INJECTION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_RAG_POISONING_PROMPT_INJECTION_TREE_JAILBREAKING`

#### ROT13

* `SECURITY_CONTEXT_LEAKAGE_ROT13`
* `SECURITY_CONTEXT_LEAKAGE_ROT13_BAD_LIKERT_JUDGE`
* `SECURITY_CONTEXT_LEAKAGE_ROT13_CRESCENDO_JAILBREAKING`
* `SECURITY_CONTEXT_LEAKAGE_ROT13_LINEAR_JAILBREAKING`
* `SECURITY_CONTEXT_LEAKAGE_ROT13_SEQUENTIAL_JAILBREAKING`
* `SECURITY_CONTEXT_LEAKAGE_ROT13_TREE_JAILBREAKING`
* `SECURITY_CONTEXT_POISONING_ROT13`
* `SECURITY_CONTEXT_POISONING_ROT13_BAD_LIKERT_JUDGE`
* `SECURITY_CONTEXT_POISONING_ROT13_CRESCENDO_JAILBREAKING`
* `SECURITY_CONTEXT_POISONING_ROT13_LINEAR_JAILBREAKING`
* `SECURITY_CONTEXT_POISONING_ROT13_SEQUENTIAL_JAILBREAKING`
* `SECURITY_CONTEXT_POISONING_ROT13_TREE_JAILBREAKING`
* `SECURITY_MANIPULATION_ROT13`
* `SECURITY_MANIPULATION_ROT13_BAD_LIKERT_JUDGE`
* `SECURITY_MANIPULATION_ROT13_CRESCENDO_JAILBREAKING`
* `SECURITY_MANIPULATION_ROT13_LINEAR_JAILBREAKING`
* `SECURITY_MANIPULATION_ROT13_SEQUENTIAL_JAILBREAKING`
* `SECURITY_MANIPULATION_ROT13_TREE_JAILBREAKING`
* `SECURITY_RAG_POISONING_ROT13`
* `SECURITY_RAG_POISONING_ROT13_BAD_LIKERT_JUDGE`
* `SECURITY_RAG_POISONING_ROT13_CRESCENDO_JAILBREAKING`
* `SECURITY_RAG_POISONING_ROT13_LINEAR_JAILBREAKING`
* `SECURITY_RAG_POISONING_ROT13_SEQUENTIAL_JAILBREAKING`
* `SECURITY_RAG_POISONING_ROT13_TREE_JAILBREAKING`

#### Roleplay

* `SECURITY_CONTEXT_LEAKAGE_ROLEPLAY`
* `SECURITY_CONTEXT_LEAKAGE_ROLEPLAY_BAD_LIKERT_JUDGE`
* `SECURITY_CONTEXT_LEAKAGE_ROLEPLAY_CRESCENDO_JAILBREAKING`
* `SECURITY_CONTEXT_LEAKAGE_ROLEPLAY_LINEAR_JAILBREAKING`
* `SECURITY_CONTEXT_LEAKAGE_ROLEPLAY_SEQUENTIAL_JAILBREAKING`
* `SECURITY_CONTEXT_LEAKAGE_ROLEPLAY_TREE_JAILBREAKING`
* `SECURITY_CONTEXT_POISONING_ROLEPLAY`
* `SECURITY_CONTEXT_POISONING_ROLEPLAY_BAD_LIKERT_JUDGE`
* `SECURITY_CONTEXT_POISONING_ROLEPLAY_CRESCENDO_JAILBREAKING`
* `SECURITY_CONTEXT_POISONING_ROLEPLAY_LINEAR_JAILBREAKING`
* `SECURITY_CONTEXT_POISONING_ROLEPLAY_SEQUENTIAL_JAILBREAKING`
* `SECURITY_CONTEXT_POISONING_ROLEPLAY_TREE_JAILBREAKING`
* `SECURITY_MANIPULATION_ROLEPLAY`
* `SECURITY_MANIPULATION_ROLEPLAY_BAD_LIKERT_JUDGE`
* `SECURITY_MANIPULATION_ROLEPLAY_CRESCENDO_JAILBREAKING`
* `SECURITY_MANIPULATION_ROLEPLAY_LINEAR_JAILBREAKING`
* `SECURITY_MANIPULATION_ROLEPLAY_SEQUENTIAL_JAILBREAKING`
* `SECURITY_MANIPULATION_ROLEPLAY_TREE_JAILBREAKING`
* `SECURITY_RAG_POISONING_ROLEPLAY`
* `SECURITY_RAG_POISONING_ROLEPLAY_BAD_LIKERT_JUDGE`
* `SECURITY_RAG_POISONING_ROLEPLAY_CRESCENDO_JAILBREAKING`
* `SECURITY_RAG_POISONING_ROLEPLAY_LINEAR_JAILBREAKING`
* `SECURITY_RAG_POISONING_ROLEPLAY_SEQUENTIAL_JAILBREAKING`
* `SECURITY_RAG_POISONING_ROLEPLAY_TREE_JAILBREAKING`

#### Semantic Manipulation

* `SECURITY_CONTEXT_LEAKAGE_SEMANTIC_MANIPULATION`
* `SECURITY_CONTEXT_LEAKAGE_SEMANTIC_MANIPULATION_BAD_LIKERT_JUDGE`
* `SECURITY_CONTEXT_LEAKAGE_SEMANTIC_MANIPULATION_CRESCENDO_JAILBREAKING`
* `SECURITY_CONTEXT_LEAKAGE_SEMANTIC_MANIPULATION_LINEAR_JAILBREAKING`
* `SECURITY_CONTEXT_LEAKAGE_SEMANTIC_MANIPULATION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_CONTEXT_LEAKAGE_SEMANTIC_MANIPULATION_TREE_JAILBREAKING`
* `SECURITY_CONTEXT_POISONING_SEMANTIC_MANIPULATION`
* `SECURITY_CONTEXT_POISONING_SEMANTIC_MANIPULATION_BAD_LIKERT_JUDGE`
* `SECURITY_CONTEXT_POISONING_SEMANTIC_MANIPULATION_CRESCENDO_JAILBREAKING`
* `SECURITY_CONTEXT_POISONING_SEMANTIC_MANIPULATION_LINEAR_JAILBREAKING`
* `SECURITY_CONTEXT_POISONING_SEMANTIC_MANIPULATION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_CONTEXT_POISONING_SEMANTIC_MANIPULATION_TREE_JAILBREAKING`
* `SECURITY_MANIPULATION_SEMANTIC_MANIPULATION`
* `SECURITY_MANIPULATION_SEMANTIC_MANIPULATION_BAD_LIKERT_JUDGE`
* `SECURITY_MANIPULATION_SEMANTIC_MANIPULATION_CRESCENDO_JAILBREAKING`
* `SECURITY_MANIPULATION_SEMANTIC_MANIPULATION_LINEAR_JAILBREAKING`
* `SECURITY_MANIPULATION_SEMANTIC_MANIPULATION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_MANIPULATION_SEMANTIC_MANIPULATION_TREE_JAILBREAKING`
* `SECURITY_RAG_POISONING_SEMANTIC_MANIPULATION`
* `SECURITY_RAG_POISONING_SEMANTIC_MANIPULATION_BAD_LIKERT_JUDGE`
* `SECURITY_RAG_POISONING_SEMANTIC_MANIPULATION_CRESCENDO_JAILBREAKING`
* `SECURITY_RAG_POISONING_SEMANTIC_MANIPULATION_LINEAR_JAILBREAKING`
* `SECURITY_RAG_POISONING_SEMANTIC_MANIPULATION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_RAG_POISONING_SEMANTIC_MANIPULATION_TREE_JAILBREAKING`

#### System Override

* `SECURITY_CONTEXT_LEAKAGE_SYSTEM_OVERRIDE`
* `SECURITY_CONTEXT_LEAKAGE_SYSTEM_OVERRIDE_BAD_LIKERT_JUDGE`
* `SECURITY_CONTEXT_LEAKAGE_SYSTEM_OVERRIDE_CRESCENDO_JAILBREAKING`
* `SECURITY_CONTEXT_LEAKAGE_SYSTEM_OVERRIDE_LINEAR_JAILBREAKING`
* `SECURITY_CONTEXT_LEAKAGE_SYSTEM_OVERRIDE_SEQUENTIAL_JAILBREAKING`
* `SECURITY_CONTEXT_LEAKAGE_SYSTEM_OVERRIDE_TREE_JAILBREAKING`
* `SECURITY_CONTEXT_POISONING_SYSTEM_OVERRIDE`
* `SECURITY_CONTEXT_POISONING_SYSTEM_OVERRIDE_BAD_LIKERT_JUDGE`
* `SECURITY_CONTEXT_POISONING_SYSTEM_OVERRIDE_CRESCENDO_JAILBREAKING`
* `SECURITY_CONTEXT_POISONING_SYSTEM_OVERRIDE_LINEAR_JAILBREAKING`
* `SECURITY_CONTEXT_POISONING_SYSTEM_OVERRIDE_SEQUENTIAL_JAILBREAKING`
* `SECURITY_CONTEXT_POISONING_SYSTEM_OVERRIDE_TREE_JAILBREAKING`
* `SECURITY_MANIPULATION_SYSTEM_OVERRIDE`
* `SECURITY_MANIPULATION_SYSTEM_OVERRIDE_BAD_LIKERT_JUDGE`
* `SECURITY_MANIPULATION_SYSTEM_OVERRIDE_CRESCENDO_JAILBREAKING`
* `SECURITY_MANIPULATION_SYSTEM_OVERRIDE_LINEAR_JAILBREAKING`
* `SECURITY_MANIPULATION_SYSTEM_OVERRIDE_SEQUENTIAL_JAILBREAKING`
* `SECURITY_MANIPULATION_SYSTEM_OVERRIDE_TREE_JAILBREAKING`
* `SECURITY_RAG_POISONING_SYSTEM_OVERRIDE`
* `SECURITY_RAG_POISONING_SYSTEM_OVERRIDE_BAD_LIKERT_JUDGE`
* `SECURITY_RAG_POISONING_SYSTEM_OVERRIDE_CRESCENDO_JAILBREAKING`
* `SECURITY_RAG_POISONING_SYSTEM_OVERRIDE_LINEAR_JAILBREAKING`
* `SECURITY_RAG_POISONING_SYSTEM_OVERRIDE_SEQUENTIAL_JAILBREAKING`
* `SECURITY_RAG_POISONING_SYSTEM_OVERRIDE_TREE_JAILBREAKING`

***

### ASI07: Insecure Inter-Agent Communication

#### Base64

* `SECURITY_CROSS_SESSION_LEAKS_BASE64`
* `SECURITY_CROSS_SESSION_LEAKS_BASE64_BAD_LIKERT_JUDGE`
* `SECURITY_CROSS_SESSION_LEAKS_BASE64_CRESCENDO_JAILBREAKING`
* `SECURITY_CROSS_SESSION_LEAKS_BASE64_LINEAR_JAILBREAKING`
* `SECURITY_CROSS_SESSION_LEAKS_BASE64_SEQUENTIAL_JAILBREAKING`
* `SECURITY_CROSS_SESSION_LEAKS_BASE64_TREE_JAILBREAKING`
* `SECURITY_DATA_EXFILTRATION_BASE64`
* `SECURITY_DATA_EXFILTRATION_BASE64_BAD_LIKERT_JUDGE`
* `SECURITY_DATA_EXFILTRATION_BASE64_CRESCENDO_JAILBREAKING`
* `SECURITY_DATA_EXFILTRATION_BASE64_LINEAR_JAILBREAKING`
* `SECURITY_DATA_EXFILTRATION_BASE64_SEQUENTIAL_JAILBREAKING`
* `SECURITY_DATA_EXFILTRATION_BASE64_TREE_JAILBREAKING`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_BASE64`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_BASE64_BAD_LIKERT_JUDGE`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_BASE64_CRESCENDO_JAILBREAKING`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_BASE64_LINEAR_JAILBREAKING`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_BASE64_SEQUENTIAL_JAILBREAKING`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_BASE64_TREE_JAILBREAKING`
* `SECURITY_REPUDIATION_UNTRACEABILITY_BASE64`
* `SECURITY_REPUDIATION_UNTRACEABILITY_BASE64_BAD_LIKERT_JUDGE`
* `SECURITY_REPUDIATION_UNTRACEABILITY_BASE64_CRESCENDO_JAILBREAKING`
* `SECURITY_REPUDIATION_UNTRACEABILITY_BASE64_LINEAR_JAILBREAKING`
* `SECURITY_REPUDIATION_UNTRACEABILITY_BASE64_SEQUENTIAL_JAILBREAKING`
* `SECURITY_REPUDIATION_UNTRACEABILITY_BASE64_TREE_JAILBREAKING`

#### Context Poisoning

* `SECURITY_CROSS_SESSION_LEAKS_CONTEXT_POISONING`
* `SECURITY_CROSS_SESSION_LEAKS_CONTEXT_POISONING_BAD_LIKERT_JUDGE`
* `SECURITY_CROSS_SESSION_LEAKS_CONTEXT_POISONING_CRESCENDO_JAILBREAKING`
* `SECURITY_CROSS_SESSION_LEAKS_CONTEXT_POISONING_LINEAR_JAILBREAKING`
* `SECURITY_CROSS_SESSION_LEAKS_CONTEXT_POISONING_SEQUENTIAL_JAILBREAKING`
* `SECURITY_CROSS_SESSION_LEAKS_CONTEXT_POISONING_TREE_JAILBREAKING`
* `SECURITY_DATA_EXFILTRATION_CONTEXT_POISONING`
* `SECURITY_DATA_EXFILTRATION_CONTEXT_POISONING_BAD_LIKERT_JUDGE`
* `SECURITY_DATA_EXFILTRATION_CONTEXT_POISONING_CRESCENDO_JAILBREAKING`
* `SECURITY_DATA_EXFILTRATION_CONTEXT_POISONING_LINEAR_JAILBREAKING`
* `SECURITY_DATA_EXFILTRATION_CONTEXT_POISONING_SEQUENTIAL_JAILBREAKING`
* `SECURITY_DATA_EXFILTRATION_CONTEXT_POISONING_TREE_JAILBREAKING`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_CONTEXT_POISONING`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_CONTEXT_POISONING_BAD_LIKERT_JUDGE`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_CONTEXT_POISONING_CRESCENDO_JAILBREAKING`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_CONTEXT_POISONING_LINEAR_JAILBREAKING`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_CONTEXT_POISONING_SEQUENTIAL_JAILBREAKING`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_CONTEXT_POISONING_TREE_JAILBREAKING`
* `SECURITY_REPUDIATION_UNTRACEABILITY_CONTEXT_POISONING`
* `SECURITY_REPUDIATION_UNTRACEABILITY_CONTEXT_POISONING_BAD_LIKERT_JUDGE`
* `SECURITY_REPUDIATION_UNTRACEABILITY_CONTEXT_POISONING_CRESCENDO_JAILBREAKING`
* `SECURITY_REPUDIATION_UNTRACEABILITY_CONTEXT_POISONING_LINEAR_JAILBREAKING`
* `SECURITY_REPUDIATION_UNTRACEABILITY_CONTEXT_POISONING_SEQUENTIAL_JAILBREAKING`
* `SECURITY_REPUDIATION_UNTRACEABILITY_CONTEXT_POISONING_TREE_JAILBREAKING`

#### Goal Redirection

* `SECURITY_CROSS_SESSION_LEAKS_GOAL_REDIRECTION`
* `SECURITY_CROSS_SESSION_LEAKS_GOAL_REDIRECTION_BAD_LIKERT_JUDGE`
* `SECURITY_CROSS_SESSION_LEAKS_GOAL_REDIRECTION_CRESCENDO_JAILBREAKING`
* `SECURITY_CROSS_SESSION_LEAKS_GOAL_REDIRECTION_LINEAR_JAILBREAKING`
* `SECURITY_CROSS_SESSION_LEAKS_GOAL_REDIRECTION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_CROSS_SESSION_LEAKS_GOAL_REDIRECTION_TREE_JAILBREAKING`
* `SECURITY_DATA_EXFILTRATION_GOAL_REDIRECTION`
* `SECURITY_DATA_EXFILTRATION_GOAL_REDIRECTION_BAD_LIKERT_JUDGE`
* `SECURITY_DATA_EXFILTRATION_GOAL_REDIRECTION_CRESCENDO_JAILBREAKING`
* `SECURITY_DATA_EXFILTRATION_GOAL_REDIRECTION_LINEAR_JAILBREAKING`
* `SECURITY_DATA_EXFILTRATION_GOAL_REDIRECTION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_DATA_EXFILTRATION_GOAL_REDIRECTION_TREE_JAILBREAKING`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_GOAL_REDIRECTION`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_GOAL_REDIRECTION_BAD_LIKERT_JUDGE`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_GOAL_REDIRECTION_CRESCENDO_JAILBREAKING`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_GOAL_REDIRECTION_LINEAR_JAILBREAKING`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_GOAL_REDIRECTION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_GOAL_REDIRECTION_TREE_JAILBREAKING`
* `SECURITY_REPUDIATION_UNTRACEABILITY_GOAL_REDIRECTION`
* `SECURITY_REPUDIATION_UNTRACEABILITY_GOAL_REDIRECTION_BAD_LIKERT_JUDGE`
* `SECURITY_REPUDIATION_UNTRACEABILITY_GOAL_REDIRECTION_CRESCENDO_JAILBREAKING`
* `SECURITY_REPUDIATION_UNTRACEABILITY_GOAL_REDIRECTION_LINEAR_JAILBREAKING`
* `SECURITY_REPUDIATION_UNTRACEABILITY_GOAL_REDIRECTION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_REPUDIATION_UNTRACEABILITY_GOAL_REDIRECTION_TREE_JAILBREAKING`

#### Input Bypass

* `SECURITY_DATA_EXFILTRATION_INPUT_BYPASS`
* `SECURITY_DATA_EXFILTRATION_INPUT_BYPASS_BAD_LIKERT_JUDGE`
* `SECURITY_DATA_EXFILTRATION_INPUT_BYPASS_CRESCENDO_JAILBREAKING`
* `SECURITY_DATA_EXFILTRATION_INPUT_BYPASS_LINEAR_JAILBREAKING`
* `SECURITY_DATA_EXFILTRATION_INPUT_BYPASS_SEQUENTIAL_JAILBREAKING`
* `SECURITY_DATA_EXFILTRATION_INPUT_BYPASS_TREE_JAILBREAKING`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_INPUT_BYPASS`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_INPUT_BYPASS_BAD_LIKERT_JUDGE`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_INPUT_BYPASS_CRESCENDO_JAILBREAKING`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_INPUT_BYPASS_LINEAR_JAILBREAKING`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_INPUT_BYPASS_SEQUENTIAL_JAILBREAKING`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_INPUT_BYPASS_TREE_JAILBREAKING`
* `SECURITY_REPUDIATION_UNTRACEABILITY_INPUT_BYPASS`
* `SECURITY_REPUDIATION_UNTRACEABILITY_INPUT_BYPASS_BAD_LIKERT_JUDGE`
* `SECURITY_REPUDIATION_UNTRACEABILITY_INPUT_BYPASS_CRESCENDO_JAILBREAKING`
* `SECURITY_REPUDIATION_UNTRACEABILITY_INPUT_BYPASS_LINEAR_JAILBREAKING`
* `SECURITY_REPUDIATION_UNTRACEABILITY_INPUT_BYPASS_SEQUENTIAL_JAILBREAKING`
* `SECURITY_REPUDIATION_UNTRACEABILITY_INPUT_BYPASS_TREE_JAILBREAKING`

#### Leetspeak

* `SECURITY_CROSS_SESSION_LEAKS_LEETSPEAK`
* `SECURITY_CROSS_SESSION_LEAKS_LEETSPEAK_BAD_LIKERT_JUDGE`
* `SECURITY_CROSS_SESSION_LEAKS_LEETSPEAK_CRESCENDO_JAILBREAKING`
* `SECURITY_CROSS_SESSION_LEAKS_LEETSPEAK_LINEAR_JAILBREAKING`
* `SECURITY_CROSS_SESSION_LEAKS_LEETSPEAK_SEQUENTIAL_JAILBREAKING`
* `SECURITY_CROSS_SESSION_LEAKS_LEETSPEAK_TREE_JAILBREAKING`
* `SECURITY_DATA_EXFILTRATION_LEETSPEAK`
* `SECURITY_DATA_EXFILTRATION_LEETSPEAK_BAD_LIKERT_JUDGE`
* `SECURITY_DATA_EXFILTRATION_LEETSPEAK_CRESCENDO_JAILBREAKING`
* `SECURITY_DATA_EXFILTRATION_LEETSPEAK_LINEAR_JAILBREAKING`
* `SECURITY_DATA_EXFILTRATION_LEETSPEAK_SEQUENTIAL_JAILBREAKING`
* `SECURITY_DATA_EXFILTRATION_LEETSPEAK_TREE_JAILBREAKING`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_LEETSPEAK`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_LEETSPEAK_BAD_LIKERT_JUDGE`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_LEETSPEAK_CRESCENDO_JAILBREAKING`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_LEETSPEAK_LINEAR_JAILBREAKING`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_LEETSPEAK_SEQUENTIAL_JAILBREAKING`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_LEETSPEAK_TREE_JAILBREAKING`
* `SECURITY_REPUDIATION_UNTRACEABILITY_LEETSPEAK`
* `SECURITY_REPUDIATION_UNTRACEABILITY_LEETSPEAK_BAD_LIKERT_JUDGE`
* `SECURITY_REPUDIATION_UNTRACEABILITY_LEETSPEAK_CRESCENDO_JAILBREAKING`
* `SECURITY_REPUDIATION_UNTRACEABILITY_LEETSPEAK_LINEAR_JAILBREAKING`
* `SECURITY_REPUDIATION_UNTRACEABILITY_LEETSPEAK_SEQUENTIAL_JAILBREAKING`
* `SECURITY_REPUDIATION_UNTRACEABILITY_LEETSPEAK_TREE_JAILBREAKING`

#### Math Problem

* `SECURITY_CROSS_SESSION_LEAKS_MATH_PROBLEM`
* `SECURITY_CROSS_SESSION_LEAKS_MATH_PROBLEM_BAD_LIKERT_JUDGE`
* `SECURITY_CROSS_SESSION_LEAKS_MATH_PROBLEM_CRESCENDO_JAILBREAKING`
* `SECURITY_CROSS_SESSION_LEAKS_MATH_PROBLEM_LINEAR_JAILBREAKING`
* `SECURITY_CROSS_SESSION_LEAKS_MATH_PROBLEM_SEQUENTIAL_JAILBREAKING`
* `SECURITY_CROSS_SESSION_LEAKS_MATH_PROBLEM_TREE_JAILBREAKING`
* `SECURITY_DATA_EXFILTRATION_MATH_PROBLEM`
* `SECURITY_DATA_EXFILTRATION_MATH_PROBLEM_BAD_LIKERT_JUDGE`
* `SECURITY_DATA_EXFILTRATION_MATH_PROBLEM_CRESCENDO_JAILBREAKING`
* `SECURITY_DATA_EXFILTRATION_MATH_PROBLEM_LINEAR_JAILBREAKING`
* `SECURITY_DATA_EXFILTRATION_MATH_PROBLEM_SEQUENTIAL_JAILBREAKING`
* `SECURITY_DATA_EXFILTRATION_MATH_PROBLEM_TREE_JAILBREAKING`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_MATH_PROBLEM`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_MATH_PROBLEM_BAD_LIKERT_JUDGE`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_MATH_PROBLEM_CRESCENDO_JAILBREAKING`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_MATH_PROBLEM_LINEAR_JAILBREAKING`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_MATH_PROBLEM_SEQUENTIAL_JAILBREAKING`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_MATH_PROBLEM_TREE_JAILBREAKING`
* `SECURITY_REPUDIATION_UNTRACEABILITY_MATH_PROBLEM`
* `SECURITY_REPUDIATION_UNTRACEABILITY_MATH_PROBLEM_BAD_LIKERT_JUDGE`
* `SECURITY_REPUDIATION_UNTRACEABILITY_MATH_PROBLEM_CRESCENDO_JAILBREAKING`
* `SECURITY_REPUDIATION_UNTRACEABILITY_MATH_PROBLEM_LINEAR_JAILBREAKING`
* `SECURITY_REPUDIATION_UNTRACEABILITY_MATH_PROBLEM_SEQUENTIAL_JAILBREAKING`
* `SECURITY_REPUDIATION_UNTRACEABILITY_MATH_PROBLEM_TREE_JAILBREAKING`

#### Multilingual

* `SECURITY_CROSS_SESSION_LEAKS_MULTILINGUAL`
* `SECURITY_CROSS_SESSION_LEAKS_MULTILINGUAL_BAD_LIKERT_JUDGE`
* `SECURITY_CROSS_SESSION_LEAKS_MULTILINGUAL_CRESCENDO_JAILBREAKING`
* `SECURITY_CROSS_SESSION_LEAKS_MULTILINGUAL_LINEAR_JAILBREAKING`
* `SECURITY_CROSS_SESSION_LEAKS_MULTILINGUAL_SEQUENTIAL_JAILBREAKING`
* `SECURITY_CROSS_SESSION_LEAKS_MULTILINGUAL_TREE_JAILBREAKING`
* `SECURITY_DATA_EXFILTRATION_MULTILINGUAL`
* `SECURITY_DATA_EXFILTRATION_MULTILINGUAL_BAD_LIKERT_JUDGE`
* `SECURITY_DATA_EXFILTRATION_MULTILINGUAL_CRESCENDO_JAILBREAKING`
* `SECURITY_DATA_EXFILTRATION_MULTILINGUAL_LINEAR_JAILBREAKING`
* `SECURITY_DATA_EXFILTRATION_MULTILINGUAL_SEQUENTIAL_JAILBREAKING`
* `SECURITY_DATA_EXFILTRATION_MULTILINGUAL_TREE_JAILBREAKING`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_MULTILINGUAL`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_MULTILINGUAL_BAD_LIKERT_JUDGE`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_MULTILINGUAL_CRESCENDO_JAILBREAKING`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_MULTILINGUAL_LINEAR_JAILBREAKING`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_MULTILINGUAL_SEQUENTIAL_JAILBREAKING`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_MULTILINGUAL_TREE_JAILBREAKING`
* `SECURITY_REPUDIATION_UNTRACEABILITY_MULTILINGUAL`
* `SECURITY_REPUDIATION_UNTRACEABILITY_MULTILINGUAL_BAD_LIKERT_JUDGE`
* `SECURITY_REPUDIATION_UNTRACEABILITY_MULTILINGUAL_CRESCENDO_JAILBREAKING`
* `SECURITY_REPUDIATION_UNTRACEABILITY_MULTILINGUAL_LINEAR_JAILBREAKING`
* `SECURITY_REPUDIATION_UNTRACEABILITY_MULTILINGUAL_SEQUENTIAL_JAILBREAKING`
* `SECURITY_REPUDIATION_UNTRACEABILITY_MULTILINGUAL_TREE_JAILBREAKING`

#### Permission Escalation

* `SECURITY_DATA_EXFILTRATION_PERMISSION_ESCALATION`
* `SECURITY_DATA_EXFILTRATION_PERMISSION_ESCALATION_BAD_LIKERT_JUDGE`
* `SECURITY_DATA_EXFILTRATION_PERMISSION_ESCALATION_CRESCENDO_JAILBREAKING`
* `SECURITY_DATA_EXFILTRATION_PERMISSION_ESCALATION_LINEAR_JAILBREAKING`
* `SECURITY_DATA_EXFILTRATION_PERMISSION_ESCALATION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_DATA_EXFILTRATION_PERMISSION_ESCALATION_TREE_JAILBREAKING`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_PERMISSION_ESCALATION`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_PERMISSION_ESCALATION_BAD_LIKERT_JUDGE`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_PERMISSION_ESCALATION_CRESCENDO_JAILBREAKING`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_PERMISSION_ESCALATION_LINEAR_JAILBREAKING`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_PERMISSION_ESCALATION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_PERMISSION_ESCALATION_TREE_JAILBREAKING`
* `SECURITY_REPUDIATION_UNTRACEABILITY_PERMISSION_ESCALATION`
* `SECURITY_REPUDIATION_UNTRACEABILITY_PERMISSION_ESCALATION_BAD_LIKERT_JUDGE`
* `SECURITY_REPUDIATION_UNTRACEABILITY_PERMISSION_ESCALATION_CRESCENDO_JAILBREAKING`
* `SECURITY_REPUDIATION_UNTRACEABILITY_PERMISSION_ESCALATION_LINEAR_JAILBREAKING`
* `SECURITY_REPUDIATION_UNTRACEABILITY_PERMISSION_ESCALATION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_REPUDIATION_UNTRACEABILITY_PERMISSION_ESCALATION_TREE_JAILBREAKING`

#### Prompt Injection

* `SECURITY_CROSS_SESSION_LEAKS_PROMPT_INJECTION`
* `SECURITY_CROSS_SESSION_LEAKS_PROMPT_INJECTION_BAD_LIKERT_JUDGE`
* `SECURITY_CROSS_SESSION_LEAKS_PROMPT_INJECTION_CRESCENDO_JAILBREAKING`
* `SECURITY_CROSS_SESSION_LEAKS_PROMPT_INJECTION_LINEAR_JAILBREAKING`
* `SECURITY_CROSS_SESSION_LEAKS_PROMPT_INJECTION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_CROSS_SESSION_LEAKS_PROMPT_INJECTION_TREE_JAILBREAKING`
* `SECURITY_DATA_EXFILTRATION_PROMPT_INJECTION`
* `SECURITY_DATA_EXFILTRATION_PROMPT_INJECTION_BAD_LIKERT_JUDGE`
* `SECURITY_DATA_EXFILTRATION_PROMPT_INJECTION_CRESCENDO_JAILBREAKING`
* `SECURITY_DATA_EXFILTRATION_PROMPT_INJECTION_LINEAR_JAILBREAKING`
* `SECURITY_DATA_EXFILTRATION_PROMPT_INJECTION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_DATA_EXFILTRATION_PROMPT_INJECTION_TREE_JAILBREAKING`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_PROMPT_INJECTION`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_PROMPT_INJECTION_BAD_LIKERT_JUDGE`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_PROMPT_INJECTION_CRESCENDO_JAILBREAKING`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_PROMPT_INJECTION_LINEAR_JAILBREAKING`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_PROMPT_INJECTION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_PROMPT_INJECTION_TREE_JAILBREAKING`
* `SECURITY_REPUDIATION_UNTRACEABILITY_PROMPT_INJECTION`
* `SECURITY_REPUDIATION_UNTRACEABILITY_PROMPT_INJECTION_BAD_LIKERT_JUDGE`
* `SECURITY_REPUDIATION_UNTRACEABILITY_PROMPT_INJECTION_CRESCENDO_JAILBREAKING`
* `SECURITY_REPUDIATION_UNTRACEABILITY_PROMPT_INJECTION_LINEAR_JAILBREAKING`
* `SECURITY_REPUDIATION_UNTRACEABILITY_PROMPT_INJECTION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_REPUDIATION_UNTRACEABILITY_PROMPT_INJECTION_TREE_JAILBREAKING`

#### ROT13

* `SECURITY_CROSS_SESSION_LEAKS_ROT13`
* `SECURITY_CROSS_SESSION_LEAKS_ROT13_BAD_LIKERT_JUDGE`
* `SECURITY_CROSS_SESSION_LEAKS_ROT13_CRESCENDO_JAILBREAKING`
* `SECURITY_CROSS_SESSION_LEAKS_ROT13_LINEAR_JAILBREAKING`
* `SECURITY_CROSS_SESSION_LEAKS_ROT13_SEQUENTIAL_JAILBREAKING`
* `SECURITY_CROSS_SESSION_LEAKS_ROT13_TREE_JAILBREAKING`
* `SECURITY_DATA_EXFILTRATION_ROT13`
* `SECURITY_DATA_EXFILTRATION_ROT13_BAD_LIKERT_JUDGE`
* `SECURITY_DATA_EXFILTRATION_ROT13_CRESCENDO_JAILBREAKING`
* `SECURITY_DATA_EXFILTRATION_ROT13_LINEAR_JAILBREAKING`
* `SECURITY_DATA_EXFILTRATION_ROT13_SEQUENTIAL_JAILBREAKING`
* `SECURITY_DATA_EXFILTRATION_ROT13_TREE_JAILBREAKING`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_ROT13`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_ROT13_BAD_LIKERT_JUDGE`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_ROT13_CRESCENDO_JAILBREAKING`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_ROT13_LINEAR_JAILBREAKING`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_ROT13_SEQUENTIAL_JAILBREAKING`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_ROT13_TREE_JAILBREAKING`
* `SECURITY_REPUDIATION_UNTRACEABILITY_ROT13`
* `SECURITY_REPUDIATION_UNTRACEABILITY_ROT13_BAD_LIKERT_JUDGE`
* `SECURITY_REPUDIATION_UNTRACEABILITY_ROT13_CRESCENDO_JAILBREAKING`
* `SECURITY_REPUDIATION_UNTRACEABILITY_ROT13_LINEAR_JAILBREAKING`
* `SECURITY_REPUDIATION_UNTRACEABILITY_ROT13_SEQUENTIAL_JAILBREAKING`
* `SECURITY_REPUDIATION_UNTRACEABILITY_ROT13_TREE_JAILBREAKING`

#### Roleplay

* `SECURITY_DATA_EXFILTRATION_ROLEPLAY`
* `SECURITY_DATA_EXFILTRATION_ROLEPLAY_BAD_LIKERT_JUDGE`
* `SECURITY_DATA_EXFILTRATION_ROLEPLAY_CRESCENDO_JAILBREAKING`
* `SECURITY_DATA_EXFILTRATION_ROLEPLAY_LINEAR_JAILBREAKING`
* `SECURITY_DATA_EXFILTRATION_ROLEPLAY_SEQUENTIAL_JAILBREAKING`
* `SECURITY_DATA_EXFILTRATION_ROLEPLAY_TREE_JAILBREAKING`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_ROLEPLAY`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_ROLEPLAY_BAD_LIKERT_JUDGE`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_ROLEPLAY_CRESCENDO_JAILBREAKING`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_ROLEPLAY_LINEAR_JAILBREAKING`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_ROLEPLAY_SEQUENTIAL_JAILBREAKING`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_ROLEPLAY_TREE_JAILBREAKING`
* `SECURITY_REPUDIATION_UNTRACEABILITY_ROLEPLAY`
* `SECURITY_REPUDIATION_UNTRACEABILITY_ROLEPLAY_BAD_LIKERT_JUDGE`
* `SECURITY_REPUDIATION_UNTRACEABILITY_ROLEPLAY_CRESCENDO_JAILBREAKING`
* `SECURITY_REPUDIATION_UNTRACEABILITY_ROLEPLAY_LINEAR_JAILBREAKING`
* `SECURITY_REPUDIATION_UNTRACEABILITY_ROLEPLAY_SEQUENTIAL_JAILBREAKING`
* `SECURITY_REPUDIATION_UNTRACEABILITY_ROLEPLAY_TREE_JAILBREAKING`

#### Semantic Manipulation

* `SECURITY_DATA_EXFILTRATION_SEMANTIC_MANIPULATION`
* `SECURITY_DATA_EXFILTRATION_SEMANTIC_MANIPULATION_BAD_LIKERT_JUDGE`
* `SECURITY_DATA_EXFILTRATION_SEMANTIC_MANIPULATION_CRESCENDO_JAILBREAKING`
* `SECURITY_DATA_EXFILTRATION_SEMANTIC_MANIPULATION_LINEAR_JAILBREAKING`
* `SECURITY_DATA_EXFILTRATION_SEMANTIC_MANIPULATION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_DATA_EXFILTRATION_SEMANTIC_MANIPULATION_TREE_JAILBREAKING`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_SEMANTIC_MANIPULATION`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_SEMANTIC_MANIPULATION_BAD_LIKERT_JUDGE`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_SEMANTIC_MANIPULATION_CRESCENDO_JAILBREAKING`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_SEMANTIC_MANIPULATION_LINEAR_JAILBREAKING`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_SEMANTIC_MANIPULATION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_SEMANTIC_MANIPULATION_TREE_JAILBREAKING`
* `SECURITY_REPUDIATION_UNTRACEABILITY_SEMANTIC_MANIPULATION`
* `SECURITY_REPUDIATION_UNTRACEABILITY_SEMANTIC_MANIPULATION_BAD_LIKERT_JUDGE`
* `SECURITY_REPUDIATION_UNTRACEABILITY_SEMANTIC_MANIPULATION_CRESCENDO_JAILBREAKING`
* `SECURITY_REPUDIATION_UNTRACEABILITY_SEMANTIC_MANIPULATION_LINEAR_JAILBREAKING`
* `SECURITY_REPUDIATION_UNTRACEABILITY_SEMANTIC_MANIPULATION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_REPUDIATION_UNTRACEABILITY_SEMANTIC_MANIPULATION_TREE_JAILBREAKING`

#### System Override

* `SECURITY_DATA_EXFILTRATION_SYSTEM_OVERRIDE`
* `SECURITY_DATA_EXFILTRATION_SYSTEM_OVERRIDE_BAD_LIKERT_JUDGE`
* `SECURITY_DATA_EXFILTRATION_SYSTEM_OVERRIDE_CRESCENDO_JAILBREAKING`
* `SECURITY_DATA_EXFILTRATION_SYSTEM_OVERRIDE_LINEAR_JAILBREAKING`
* `SECURITY_DATA_EXFILTRATION_SYSTEM_OVERRIDE_SEQUENTIAL_JAILBREAKING`
* `SECURITY_DATA_EXFILTRATION_SYSTEM_OVERRIDE_TREE_JAILBREAKING`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_SYSTEM_OVERRIDE`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_SYSTEM_OVERRIDE_BAD_LIKERT_JUDGE`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_SYSTEM_OVERRIDE_CRESCENDO_JAILBREAKING`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_SYSTEM_OVERRIDE_LINEAR_JAILBREAKING`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_SYSTEM_OVERRIDE_SEQUENTIAL_JAILBREAKING`
* `SECURITY_INSECURE_INTER_AGENT_COMMUNICATION_SYSTEM_OVERRIDE_TREE_JAILBREAKING`
* `SECURITY_REPUDIATION_UNTRACEABILITY_SYSTEM_OVERRIDE`
* `SECURITY_REPUDIATION_UNTRACEABILITY_SYSTEM_OVERRIDE_BAD_LIKERT_JUDGE`
* `SECURITY_REPUDIATION_UNTRACEABILITY_SYSTEM_OVERRIDE_CRESCENDO_JAILBREAKING`
* `SECURITY_REPUDIATION_UNTRACEABILITY_SYSTEM_OVERRIDE_LINEAR_JAILBREAKING`
* `SECURITY_REPUDIATION_UNTRACEABILITY_SYSTEM_OVERRIDE_SEQUENTIAL_JAILBREAKING`
* `SECURITY_REPUDIATION_UNTRACEABILITY_SYSTEM_OVERRIDE_TREE_JAILBREAKING`

***

### ASI08: Cascading Failures

#### Base64

* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_BASE64`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_BASE64_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_BASE64_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_BASE64_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_BASE64_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_BASE64_TREE_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_BASE64`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_BASE64_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_BASE64_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_BASE64_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_BASE64_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_BASE64_TREE_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_BASE64`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_BASE64_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_BASE64_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_BASE64_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_BASE64_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_BASE64_TREE_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_BASE64`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_BASE64_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_BASE64_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_BASE64_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_BASE64_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_BASE64_TREE_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_BASE64`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_BASE64_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_BASE64_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_BASE64_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_BASE64_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_BASE64_TREE_JAILBREAKING`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_BASE64`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_BASE64_BAD_LIKERT_JUDGE`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_BASE64_CRESCENDO_JAILBREAKING`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_BASE64_LINEAR_JAILBREAKING`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_BASE64_SEQUENTIAL_JAILBREAKING`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_BASE64_TREE_JAILBREAKING`

#### Context Poisoning

* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_CONTEXT_POISONING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_CONTEXT_POISONING_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_CONTEXT_POISONING_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_CONTEXT_POISONING_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_CONTEXT_POISONING_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_CONTEXT_POISONING_TREE_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_CONTEXT_POISONING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_CONTEXT_POISONING_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_CONTEXT_POISONING_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_CONTEXT_POISONING_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_CONTEXT_POISONING_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_CONTEXT_POISONING_TREE_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_CONTEXT_POISONING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_CONTEXT_POISONING_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_CONTEXT_POISONING_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_CONTEXT_POISONING_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_CONTEXT_POISONING_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_CONTEXT_POISONING_TREE_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_CONTEXT_POISONING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_CONTEXT_POISONING_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_CONTEXT_POISONING_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_CONTEXT_POISONING_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_CONTEXT_POISONING_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_CONTEXT_POISONING_TREE_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_CONTEXT_POISONING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_CONTEXT_POISONING_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_CONTEXT_POISONING_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_CONTEXT_POISONING_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_CONTEXT_POISONING_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_CONTEXT_POISONING_TREE_JAILBREAKING`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_CONTEXT_POISONING`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_CONTEXT_POISONING_BAD_LIKERT_JUDGE`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_CONTEXT_POISONING_CRESCENDO_JAILBREAKING`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_CONTEXT_POISONING_LINEAR_JAILBREAKING`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_CONTEXT_POISONING_SEQUENTIAL_JAILBREAKING`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_CONTEXT_POISONING_TREE_JAILBREAKING`

#### Goal Redirection

* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_GOAL_REDIRECTION`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_GOAL_REDIRECTION_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_GOAL_REDIRECTION_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_GOAL_REDIRECTION_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_GOAL_REDIRECTION_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_GOAL_REDIRECTION_TREE_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_GOAL_REDIRECTION`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_GOAL_REDIRECTION_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_GOAL_REDIRECTION_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_GOAL_REDIRECTION_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_GOAL_REDIRECTION_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_GOAL_REDIRECTION_TREE_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_GOAL_REDIRECTION`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_GOAL_REDIRECTION_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_GOAL_REDIRECTION_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_GOAL_REDIRECTION_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_GOAL_REDIRECTION_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_GOAL_REDIRECTION_TREE_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_GOAL_REDIRECTION`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_GOAL_REDIRECTION_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_GOAL_REDIRECTION_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_GOAL_REDIRECTION_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_GOAL_REDIRECTION_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_GOAL_REDIRECTION_TREE_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_GOAL_REDIRECTION`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_GOAL_REDIRECTION_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_GOAL_REDIRECTION_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_GOAL_REDIRECTION_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_GOAL_REDIRECTION_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_GOAL_REDIRECTION_TREE_JAILBREAKING`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_GOAL_REDIRECTION`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_GOAL_REDIRECTION_BAD_LIKERT_JUDGE`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_GOAL_REDIRECTION_CRESCENDO_JAILBREAKING`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_GOAL_REDIRECTION_LINEAR_JAILBREAKING`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_GOAL_REDIRECTION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_GOAL_REDIRECTION_TREE_JAILBREAKING`

#### Input Bypass

* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_INPUT_BYPASS`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_INPUT_BYPASS_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_INPUT_BYPASS_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_INPUT_BYPASS_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_INPUT_BYPASS_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_INPUT_BYPASS_TREE_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_INPUT_BYPASS`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_INPUT_BYPASS_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_INPUT_BYPASS_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_INPUT_BYPASS_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_INPUT_BYPASS_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_INPUT_BYPASS_TREE_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_INPUT_BYPASS`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_INPUT_BYPASS_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_INPUT_BYPASS_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_INPUT_BYPASS_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_INPUT_BYPASS_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_INPUT_BYPASS_TREE_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_INPUT_BYPASS`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_INPUT_BYPASS_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_INPUT_BYPASS_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_INPUT_BYPASS_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_INPUT_BYPASS_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_INPUT_BYPASS_TREE_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_INPUT_BYPASS`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_INPUT_BYPASS_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_INPUT_BYPASS_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_INPUT_BYPASS_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_INPUT_BYPASS_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_INPUT_BYPASS_TREE_JAILBREAKING`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_INPUT_BYPASS`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_INPUT_BYPASS_BAD_LIKERT_JUDGE`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_INPUT_BYPASS_CRESCENDO_JAILBREAKING`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_INPUT_BYPASS_LINEAR_JAILBREAKING`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_INPUT_BYPASS_SEQUENTIAL_JAILBREAKING`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_INPUT_BYPASS_TREE_JAILBREAKING`

#### Leetspeak

* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_LEETSPEAK`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_LEETSPEAK_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_LEETSPEAK_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_LEETSPEAK_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_LEETSPEAK_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_LEETSPEAK_TREE_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_LEETSPEAK`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_LEETSPEAK_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_LEETSPEAK_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_LEETSPEAK_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_LEETSPEAK_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_LEETSPEAK_TREE_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_LEETSPEAK`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_LEETSPEAK_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_LEETSPEAK_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_LEETSPEAK_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_LEETSPEAK_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_LEETSPEAK_TREE_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_LEETSPEAK`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_LEETSPEAK_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_LEETSPEAK_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_LEETSPEAK_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_LEETSPEAK_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_LEETSPEAK_TREE_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_LEETSPEAK`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_LEETSPEAK_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_LEETSPEAK_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_LEETSPEAK_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_LEETSPEAK_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_LEETSPEAK_TREE_JAILBREAKING`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_LEETSPEAK`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_LEETSPEAK_BAD_LIKERT_JUDGE`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_LEETSPEAK_CRESCENDO_JAILBREAKING`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_LEETSPEAK_LINEAR_JAILBREAKING`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_LEETSPEAK_SEQUENTIAL_JAILBREAKING`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_LEETSPEAK_TREE_JAILBREAKING`

#### Math Problem

* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_MATH_PROBLEM`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_MATH_PROBLEM_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_MATH_PROBLEM_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_MATH_PROBLEM_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_MATH_PROBLEM_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_MATH_PROBLEM_TREE_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_MATH_PROBLEM`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_MATH_PROBLEM_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_MATH_PROBLEM_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_MATH_PROBLEM_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_MATH_PROBLEM_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_MATH_PROBLEM_TREE_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_MATH_PROBLEM`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_MATH_PROBLEM_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_MATH_PROBLEM_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_MATH_PROBLEM_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_MATH_PROBLEM_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_MATH_PROBLEM_TREE_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_MATH_PROBLEM`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_MATH_PROBLEM_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_MATH_PROBLEM_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_MATH_PROBLEM_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_MATH_PROBLEM_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_MATH_PROBLEM_TREE_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_MATH_PROBLEM`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_MATH_PROBLEM_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_MATH_PROBLEM_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_MATH_PROBLEM_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_MATH_PROBLEM_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_MATH_PROBLEM_TREE_JAILBREAKING`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_MATH_PROBLEM`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_MATH_PROBLEM_BAD_LIKERT_JUDGE`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_MATH_PROBLEM_CRESCENDO_JAILBREAKING`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_MATH_PROBLEM_LINEAR_JAILBREAKING`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_MATH_PROBLEM_SEQUENTIAL_JAILBREAKING`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_MATH_PROBLEM_TREE_JAILBREAKING`

#### Multilingual

* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_MULTILINGUAL`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_MULTILINGUAL_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_MULTILINGUAL_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_MULTILINGUAL_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_MULTILINGUAL_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_MULTILINGUAL_TREE_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_MULTILINGUAL`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_MULTILINGUAL_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_MULTILINGUAL_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_MULTILINGUAL_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_MULTILINGUAL_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_MULTILINGUAL_TREE_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_MULTILINGUAL`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_MULTILINGUAL_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_MULTILINGUAL_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_MULTILINGUAL_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_MULTILINGUAL_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_MULTILINGUAL_TREE_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_MULTILINGUAL`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_MULTILINGUAL_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_MULTILINGUAL_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_MULTILINGUAL_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_MULTILINGUAL_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_MULTILINGUAL_TREE_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_MULTILINGUAL`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_MULTILINGUAL_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_MULTILINGUAL_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_MULTILINGUAL_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_MULTILINGUAL_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_MULTILINGUAL_TREE_JAILBREAKING`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_MULTILINGUAL`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_MULTILINGUAL_BAD_LIKERT_JUDGE`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_MULTILINGUAL_CRESCENDO_JAILBREAKING`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_MULTILINGUAL_LINEAR_JAILBREAKING`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_MULTILINGUAL_SEQUENTIAL_JAILBREAKING`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_MULTILINGUAL_TREE_JAILBREAKING`

#### Permission Escalation

* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_PERMISSION_ESCALATION`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_PERMISSION_ESCALATION_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_PERMISSION_ESCALATION_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_PERMISSION_ESCALATION_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_PERMISSION_ESCALATION_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_PERMISSION_ESCALATION_TREE_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_PERMISSION_ESCALATION`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_PERMISSION_ESCALATION_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_PERMISSION_ESCALATION_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_PERMISSION_ESCALATION_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_PERMISSION_ESCALATION_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_PERMISSION_ESCALATION_TREE_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_PERMISSION_ESCALATION`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_PERMISSION_ESCALATION_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_PERMISSION_ESCALATION_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_PERMISSION_ESCALATION_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_PERMISSION_ESCALATION_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_PERMISSION_ESCALATION_TREE_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_PERMISSION_ESCALATION`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_PERMISSION_ESCALATION_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_PERMISSION_ESCALATION_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_PERMISSION_ESCALATION_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_PERMISSION_ESCALATION_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_PERMISSION_ESCALATION_TREE_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_PERMISSION_ESCALATION`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_PERMISSION_ESCALATION_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_PERMISSION_ESCALATION_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_PERMISSION_ESCALATION_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_PERMISSION_ESCALATION_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_PERMISSION_ESCALATION_TREE_JAILBREAKING`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_PERMISSION_ESCALATION`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_PERMISSION_ESCALATION_BAD_LIKERT_JUDGE`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_PERMISSION_ESCALATION_CRESCENDO_JAILBREAKING`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_PERMISSION_ESCALATION_LINEAR_JAILBREAKING`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_PERMISSION_ESCALATION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_PERMISSION_ESCALATION_TREE_JAILBREAKING`

#### Prompt Injection

* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_PROMPT_INJECTION`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_PROMPT_INJECTION_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_PROMPT_INJECTION_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_PROMPT_INJECTION_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_PROMPT_INJECTION_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_PROMPT_INJECTION_TREE_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_PROMPT_INJECTION`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_PROMPT_INJECTION_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_PROMPT_INJECTION_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_PROMPT_INJECTION_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_PROMPT_INJECTION_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_PROMPT_INJECTION_TREE_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_PROMPT_INJECTION`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_PROMPT_INJECTION_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_PROMPT_INJECTION_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_PROMPT_INJECTION_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_PROMPT_INJECTION_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_PROMPT_INJECTION_TREE_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_PROMPT_INJECTION`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_PROMPT_INJECTION_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_PROMPT_INJECTION_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_PROMPT_INJECTION_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_PROMPT_INJECTION_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_PROMPT_INJECTION_TREE_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_PROMPT_INJECTION`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_PROMPT_INJECTION_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_PROMPT_INJECTION_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_PROMPT_INJECTION_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_PROMPT_INJECTION_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_PROMPT_INJECTION_TREE_JAILBREAKING`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_PROMPT_INJECTION`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_PROMPT_INJECTION_BAD_LIKERT_JUDGE`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_PROMPT_INJECTION_CRESCENDO_JAILBREAKING`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_PROMPT_INJECTION_LINEAR_JAILBREAKING`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_PROMPT_INJECTION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_PROMPT_INJECTION_TREE_JAILBREAKING`

#### ROT13

* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_ROT13`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_ROT13_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_ROT13_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_ROT13_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_ROT13_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_ROT13_TREE_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_ROT13`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_ROT13_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_ROT13_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_ROT13_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_ROT13_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_ROT13_TREE_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_ROT13`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_ROT13_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_ROT13_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_ROT13_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_ROT13_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_ROT13_TREE_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_ROT13`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_ROT13_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_ROT13_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_ROT13_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_ROT13_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_ROT13_TREE_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_ROT13`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_ROT13_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_ROT13_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_ROT13_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_ROT13_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_ROT13_TREE_JAILBREAKING`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_ROT13`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_ROT13_BAD_LIKERT_JUDGE`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_ROT13_CRESCENDO_JAILBREAKING`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_ROT13_LINEAR_JAILBREAKING`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_ROT13_SEQUENTIAL_JAILBREAKING`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_ROT13_TREE_JAILBREAKING`

#### Roleplay

* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_ROLEPLAY`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_ROLEPLAY_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_ROLEPLAY_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_ROLEPLAY_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_ROLEPLAY_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_ROLEPLAY_TREE_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_ROLEPLAY`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_ROLEPLAY_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_ROLEPLAY_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_ROLEPLAY_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_ROLEPLAY_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_ROLEPLAY_TREE_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_ROLEPLAY`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_ROLEPLAY_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_ROLEPLAY_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_ROLEPLAY_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_ROLEPLAY_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_ROLEPLAY_TREE_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_ROLEPLAY`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_ROLEPLAY_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_ROLEPLAY_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_ROLEPLAY_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_ROLEPLAY_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_ROLEPLAY_TREE_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_ROLEPLAY`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_ROLEPLAY_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_ROLEPLAY_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_ROLEPLAY_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_ROLEPLAY_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_ROLEPLAY_TREE_JAILBREAKING`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_ROLEPLAY`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_ROLEPLAY_BAD_LIKERT_JUDGE`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_ROLEPLAY_CRESCENDO_JAILBREAKING`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_ROLEPLAY_LINEAR_JAILBREAKING`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_ROLEPLAY_SEQUENTIAL_JAILBREAKING`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_ROLEPLAY_TREE_JAILBREAKING`

#### Semantic Manipulation

* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_SEMANTIC_MANIPULATION`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_SEMANTIC_MANIPULATION_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_SEMANTIC_MANIPULATION_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_SEMANTIC_MANIPULATION_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_SEMANTIC_MANIPULATION_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_SEMANTIC_MANIPULATION_TREE_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_SEMANTIC_MANIPULATION`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_SEMANTIC_MANIPULATION_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_SEMANTIC_MANIPULATION_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_SEMANTIC_MANIPULATION_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_SEMANTIC_MANIPULATION_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_SEMANTIC_MANIPULATION_TREE_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_SEMANTIC_MANIPULATION`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_SEMANTIC_MANIPULATION_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_SEMANTIC_MANIPULATION_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_SEMANTIC_MANIPULATION_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_SEMANTIC_MANIPULATION_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_SEMANTIC_MANIPULATION_TREE_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_SEMANTIC_MANIPULATION`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_SEMANTIC_MANIPULATION_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_SEMANTIC_MANIPULATION_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_SEMANTIC_MANIPULATION_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_SEMANTIC_MANIPULATION_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_SEMANTIC_MANIPULATION_TREE_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_SEMANTIC_MANIPULATION`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_SEMANTIC_MANIPULATION_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_SEMANTIC_MANIPULATION_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_SEMANTIC_MANIPULATION_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_SEMANTIC_MANIPULATION_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_SEMANTIC_MANIPULATION_TREE_JAILBREAKING`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_SEMANTIC_MANIPULATION`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_SEMANTIC_MANIPULATION_BAD_LIKERT_JUDGE`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_SEMANTIC_MANIPULATION_CRESCENDO_JAILBREAKING`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_SEMANTIC_MANIPULATION_LINEAR_JAILBREAKING`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_SEMANTIC_MANIPULATION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_SEMANTIC_MANIPULATION_TREE_JAILBREAKING`

#### System Override

* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_SYSTEM_OVERRIDE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_SYSTEM_OVERRIDE_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_SYSTEM_OVERRIDE_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_SYSTEM_OVERRIDE_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_SYSTEM_OVERRIDE_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_HALLUCINATION_PROPAGATION_SYSTEM_OVERRIDE_TREE_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_SYSTEM_OVERRIDE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_SYSTEM_OVERRIDE_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_SYSTEM_OVERRIDE_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_SYSTEM_OVERRIDE_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_SYSTEM_OVERRIDE_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_PARANOID_PROTECTION_SYSTEM_OVERRIDE_TREE_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_SYSTEM_OVERRIDE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_SYSTEM_OVERRIDE_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_SYSTEM_OVERRIDE_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_SYSTEM_OVERRIDE_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_SYSTEM_OVERRIDE_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_Q_A_SYSTEM_OVERRIDE_TREE_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_SYSTEM_OVERRIDE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_SYSTEM_OVERRIDE_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_SYSTEM_OVERRIDE_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_SYSTEM_OVERRIDE_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_SYSTEM_OVERRIDE_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_RAG_PRECISION_SYSTEM_OVERRIDE_TREE_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_SYSTEM_OVERRIDE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_SYSTEM_OVERRIDE_BAD_LIKERT_JUDGE`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_SYSTEM_OVERRIDE_CRESCENDO_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_SYSTEM_OVERRIDE_LINEAR_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_SYSTEM_OVERRIDE_SEQUENTIAL_JAILBREAKING`
* `HALLUCINATION_AND_TRUSTWORTHINESS_URL_CHECK_SYSTEM_OVERRIDE_TREE_JAILBREAKING`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_SYSTEM_OVERRIDE`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_SYSTEM_OVERRIDE_BAD_LIKERT_JUDGE`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_SYSTEM_OVERRIDE_CRESCENDO_JAILBREAKING`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_SYSTEM_OVERRIDE_LINEAR_JAILBREAKING`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_SYSTEM_OVERRIDE_SEQUENTIAL_JAILBREAKING`
* `SECURITY_MODEL_DENIAL_OF_SERVICE_SYSTEM_OVERRIDE_TREE_JAILBREAKING`

***

### ASI09: Human-Agent Trust Exploitation

#### Base64

* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_BASE64`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_BASE64_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_BASE64_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_BASE64_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_BASE64_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_BASE64_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_BASE64`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_BASE64_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_BASE64_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_BASE64_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_BASE64_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_BASE64_TREE_JAILBREAKING`
* `SAFETY_BIAS_BASE64`
* `SAFETY_BIAS_BASE64_BAD_LIKERT_JUDGE`
* `SAFETY_BIAS_BASE64_CRESCENDO_JAILBREAKING`
* `SAFETY_BIAS_BASE64_LINEAR_JAILBREAKING`
* `SAFETY_BIAS_BASE64_SEQUENTIAL_JAILBREAKING`
* `SAFETY_BIAS_BASE64_TREE_JAILBREAKING`
* `SAFETY_HARMFUL_CONTENT_BASE64`
* `SAFETY_HARMFUL_CONTENT_BASE64_BAD_LIKERT_JUDGE`
* `SAFETY_HARMFUL_CONTENT_BASE64_CRESCENDO_JAILBREAKING`
* `SAFETY_HARMFUL_CONTENT_BASE64_LINEAR_JAILBREAKING`
* `SAFETY_HARMFUL_CONTENT_BASE64_SEQUENTIAL_JAILBREAKING`
* `SAFETY_HARMFUL_CONTENT_BASE64_TREE_JAILBREAKING`
* `SAFETY_ILLEGAL_ACTIVITIES_BASE64`
* `SAFETY_ILLEGAL_ACTIVITIES_BASE64_BAD_LIKERT_JUDGE`
* `SAFETY_ILLEGAL_ACTIVITIES_BASE64_CRESCENDO_JAILBREAKING`
* `SAFETY_ILLEGAL_ACTIVITIES_BASE64_LINEAR_JAILBREAKING`
* `SAFETY_ILLEGAL_ACTIVITIES_BASE64_SEQUENTIAL_JAILBREAKING`
* `SAFETY_ILLEGAL_ACTIVITIES_BASE64_TREE_JAILBREAKING`
* `SAFETY_PROFANITY_BASE64`
* `SAFETY_PROFANITY_BASE64_BAD_LIKERT_JUDGE`
* `SAFETY_PROFANITY_BASE64_CRESCENDO_JAILBREAKING`
* `SAFETY_PROFANITY_BASE64_LINEAR_JAILBREAKING`
* `SAFETY_PROFANITY_BASE64_SEQUENTIAL_JAILBREAKING`
* `SAFETY_PROFANITY_BASE64_TREE_JAILBREAKING`
* `SECURITY_OVERRELIANCE_BASE64`
* `SECURITY_OVERRELIANCE_BASE64_BAD_LIKERT_JUDGE`
* `SECURITY_OVERRELIANCE_BASE64_CRESCENDO_JAILBREAKING`
* `SECURITY_OVERRELIANCE_BASE64_LINEAR_JAILBREAKING`
* `SECURITY_OVERRELIANCE_BASE64_SEQUENTIAL_JAILBREAKING`
* `SECURITY_OVERRELIANCE_BASE64_TREE_JAILBREAKING`

#### Context Poisoning

* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_CONTEXT_POISONING`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_CONTEXT_POISONING_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_CONTEXT_POISONING_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_CONTEXT_POISONING_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_CONTEXT_POISONING_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_CONTEXT_POISONING_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_CONTEXT_POISONING`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_CONTEXT_POISONING_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_CONTEXT_POISONING_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_CONTEXT_POISONING_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_CONTEXT_POISONING_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_CONTEXT_POISONING_TREE_JAILBREAKING`
* `SAFETY_BIAS_CONTEXT_POISONING`
* `SAFETY_BIAS_CONTEXT_POISONING_BAD_LIKERT_JUDGE`
* `SAFETY_BIAS_CONTEXT_POISONING_CRESCENDO_JAILBREAKING`
* `SAFETY_BIAS_CONTEXT_POISONING_LINEAR_JAILBREAKING`
* `SAFETY_BIAS_CONTEXT_POISONING_SEQUENTIAL_JAILBREAKING`
* `SAFETY_BIAS_CONTEXT_POISONING_TREE_JAILBREAKING`
* `SAFETY_HARMFUL_CONTENT_CONTEXT_POISONING`
* `SAFETY_HARMFUL_CONTENT_CONTEXT_POISONING_BAD_LIKERT_JUDGE`
* `SAFETY_HARMFUL_CONTENT_CONTEXT_POISONING_CRESCENDO_JAILBREAKING`
* `SAFETY_HARMFUL_CONTENT_CONTEXT_POISONING_LINEAR_JAILBREAKING`
* `SAFETY_HARMFUL_CONTENT_CONTEXT_POISONING_SEQUENTIAL_JAILBREAKING`
* `SAFETY_HARMFUL_CONTENT_CONTEXT_POISONING_TREE_JAILBREAKING`
* `SAFETY_ILLEGAL_ACTIVITIES_CONTEXT_POISONING`
* `SAFETY_ILLEGAL_ACTIVITIES_CONTEXT_POISONING_BAD_LIKERT_JUDGE`
* `SAFETY_ILLEGAL_ACTIVITIES_CONTEXT_POISONING_CRESCENDO_JAILBREAKING`
* `SAFETY_ILLEGAL_ACTIVITIES_CONTEXT_POISONING_LINEAR_JAILBREAKING`
* `SAFETY_ILLEGAL_ACTIVITIES_CONTEXT_POISONING_SEQUENTIAL_JAILBREAKING`
* `SAFETY_ILLEGAL_ACTIVITIES_CONTEXT_POISONING_TREE_JAILBREAKING`
* `SAFETY_PROFANITY_CONTEXT_POISONING`
* `SAFETY_PROFANITY_CONTEXT_POISONING_BAD_LIKERT_JUDGE`
* `SAFETY_PROFANITY_CONTEXT_POISONING_CRESCENDO_JAILBREAKING`
* `SAFETY_PROFANITY_CONTEXT_POISONING_LINEAR_JAILBREAKING`
* `SAFETY_PROFANITY_CONTEXT_POISONING_SEQUENTIAL_JAILBREAKING`
* `SAFETY_PROFANITY_CONTEXT_POISONING_TREE_JAILBREAKING`
* `SECURITY_OVERRELIANCE_CONTEXT_POISONING`
* `SECURITY_OVERRELIANCE_CONTEXT_POISONING_BAD_LIKERT_JUDGE`
* `SECURITY_OVERRELIANCE_CONTEXT_POISONING_CRESCENDO_JAILBREAKING`
* `SECURITY_OVERRELIANCE_CONTEXT_POISONING_LINEAR_JAILBREAKING`
* `SECURITY_OVERRELIANCE_CONTEXT_POISONING_SEQUENTIAL_JAILBREAKING`
* `SECURITY_OVERRELIANCE_CONTEXT_POISONING_TREE_JAILBREAKING`

#### Goal Redirection

* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_GOAL_REDIRECTION`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_GOAL_REDIRECTION_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_GOAL_REDIRECTION_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_GOAL_REDIRECTION_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_GOAL_REDIRECTION_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_GOAL_REDIRECTION_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_GOAL_REDIRECTION`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_GOAL_REDIRECTION_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_GOAL_REDIRECTION_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_GOAL_REDIRECTION_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_GOAL_REDIRECTION_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_GOAL_REDIRECTION_TREE_JAILBREAKING`
* `SAFETY_BIAS_GOAL_REDIRECTION`
* `SAFETY_BIAS_GOAL_REDIRECTION_BAD_LIKERT_JUDGE`
* `SAFETY_BIAS_GOAL_REDIRECTION_CRESCENDO_JAILBREAKING`
* `SAFETY_BIAS_GOAL_REDIRECTION_LINEAR_JAILBREAKING`
* `SAFETY_BIAS_GOAL_REDIRECTION_SEQUENTIAL_JAILBREAKING`
* `SAFETY_BIAS_GOAL_REDIRECTION_TREE_JAILBREAKING`
* `SAFETY_HARMFUL_CONTENT_GOAL_REDIRECTION`
* `SAFETY_HARMFUL_CONTENT_GOAL_REDIRECTION_BAD_LIKERT_JUDGE`
* `SAFETY_HARMFUL_CONTENT_GOAL_REDIRECTION_CRESCENDO_JAILBREAKING`
* `SAFETY_HARMFUL_CONTENT_GOAL_REDIRECTION_LINEAR_JAILBREAKING`
* `SAFETY_HARMFUL_CONTENT_GOAL_REDIRECTION_SEQUENTIAL_JAILBREAKING`
* `SAFETY_HARMFUL_CONTENT_GOAL_REDIRECTION_TREE_JAILBREAKING`
* `SAFETY_ILLEGAL_ACTIVITIES_GOAL_REDIRECTION`
* `SAFETY_ILLEGAL_ACTIVITIES_GOAL_REDIRECTION_BAD_LIKERT_JUDGE`
* `SAFETY_ILLEGAL_ACTIVITIES_GOAL_REDIRECTION_CRESCENDO_JAILBREAKING`
* `SAFETY_ILLEGAL_ACTIVITIES_GOAL_REDIRECTION_LINEAR_JAILBREAKING`
* `SAFETY_ILLEGAL_ACTIVITIES_GOAL_REDIRECTION_SEQUENTIAL_JAILBREAKING`
* `SAFETY_ILLEGAL_ACTIVITIES_GOAL_REDIRECTION_TREE_JAILBREAKING`
* `SAFETY_PROFANITY_GOAL_REDIRECTION`
* `SAFETY_PROFANITY_GOAL_REDIRECTION_BAD_LIKERT_JUDGE`
* `SAFETY_PROFANITY_GOAL_REDIRECTION_CRESCENDO_JAILBREAKING`
* `SAFETY_PROFANITY_GOAL_REDIRECTION_LINEAR_JAILBREAKING`
* `SAFETY_PROFANITY_GOAL_REDIRECTION_SEQUENTIAL_JAILBREAKING`
* `SAFETY_PROFANITY_GOAL_REDIRECTION_TREE_JAILBREAKING`
* `SECURITY_OVERRELIANCE_GOAL_REDIRECTION`
* `SECURITY_OVERRELIANCE_GOAL_REDIRECTION_BAD_LIKERT_JUDGE`
* `SECURITY_OVERRELIANCE_GOAL_REDIRECTION_CRESCENDO_JAILBREAKING`
* `SECURITY_OVERRELIANCE_GOAL_REDIRECTION_LINEAR_JAILBREAKING`
* `SECURITY_OVERRELIANCE_GOAL_REDIRECTION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_OVERRELIANCE_GOAL_REDIRECTION_TREE_JAILBREAKING`

#### Input Bypass

* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_INPUT_BYPASS`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_INPUT_BYPASS_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_INPUT_BYPASS_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_INPUT_BYPASS_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_INPUT_BYPASS_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_INPUT_BYPASS_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_INPUT_BYPASS`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_INPUT_BYPASS_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_INPUT_BYPASS_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_INPUT_BYPASS_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_INPUT_BYPASS_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_INPUT_BYPASS_TREE_JAILBREAKING`
* `SAFETY_BIAS_INPUT_BYPASS`
* `SAFETY_BIAS_INPUT_BYPASS_BAD_LIKERT_JUDGE`
* `SAFETY_BIAS_INPUT_BYPASS_CRESCENDO_JAILBREAKING`
* `SAFETY_BIAS_INPUT_BYPASS_LINEAR_JAILBREAKING`
* `SAFETY_BIAS_INPUT_BYPASS_SEQUENTIAL_JAILBREAKING`
* `SAFETY_BIAS_INPUT_BYPASS_TREE_JAILBREAKING`
* `SAFETY_HARMFUL_CONTENT_INPUT_BYPASS`
* `SAFETY_HARMFUL_CONTENT_INPUT_BYPASS_BAD_LIKERT_JUDGE`
* `SAFETY_HARMFUL_CONTENT_INPUT_BYPASS_CRESCENDO_JAILBREAKING`
* `SAFETY_HARMFUL_CONTENT_INPUT_BYPASS_LINEAR_JAILBREAKING`
* `SAFETY_HARMFUL_CONTENT_INPUT_BYPASS_SEQUENTIAL_JAILBREAKING`
* `SAFETY_HARMFUL_CONTENT_INPUT_BYPASS_TREE_JAILBREAKING`
* `SAFETY_ILLEGAL_ACTIVITIES_INPUT_BYPASS`
* `SAFETY_ILLEGAL_ACTIVITIES_INPUT_BYPASS_BAD_LIKERT_JUDGE`
* `SAFETY_ILLEGAL_ACTIVITIES_INPUT_BYPASS_CRESCENDO_JAILBREAKING`
* `SAFETY_ILLEGAL_ACTIVITIES_INPUT_BYPASS_LINEAR_JAILBREAKING`
* `SAFETY_ILLEGAL_ACTIVITIES_INPUT_BYPASS_SEQUENTIAL_JAILBREAKING`
* `SAFETY_ILLEGAL_ACTIVITIES_INPUT_BYPASS_TREE_JAILBREAKING`
* `SAFETY_PROFANITY_INPUT_BYPASS`
* `SAFETY_PROFANITY_INPUT_BYPASS_BAD_LIKERT_JUDGE`
* `SAFETY_PROFANITY_INPUT_BYPASS_CRESCENDO_JAILBREAKING`
* `SAFETY_PROFANITY_INPUT_BYPASS_LINEAR_JAILBREAKING`
* `SAFETY_PROFANITY_INPUT_BYPASS_SEQUENTIAL_JAILBREAKING`
* `SAFETY_PROFANITY_INPUT_BYPASS_TREE_JAILBREAKING`
* `SECURITY_OVERRELIANCE_INPUT_BYPASS`
* `SECURITY_OVERRELIANCE_INPUT_BYPASS_BAD_LIKERT_JUDGE`
* `SECURITY_OVERRELIANCE_INPUT_BYPASS_CRESCENDO_JAILBREAKING`
* `SECURITY_OVERRELIANCE_INPUT_BYPASS_LINEAR_JAILBREAKING`
* `SECURITY_OVERRELIANCE_INPUT_BYPASS_SEQUENTIAL_JAILBREAKING`
* `SECURITY_OVERRELIANCE_INPUT_BYPASS_TREE_JAILBREAKING`

#### Leetspeak

* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_LEETSPEAK`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_LEETSPEAK_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_LEETSPEAK_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_LEETSPEAK_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_LEETSPEAK_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_LEETSPEAK_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_LEETSPEAK`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_LEETSPEAK_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_LEETSPEAK_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_LEETSPEAK_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_LEETSPEAK_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_LEETSPEAK_TREE_JAILBREAKING`
* `SAFETY_BIAS_LEETSPEAK`
* `SAFETY_BIAS_LEETSPEAK_BAD_LIKERT_JUDGE`
* `SAFETY_BIAS_LEETSPEAK_CRESCENDO_JAILBREAKING`
* `SAFETY_BIAS_LEETSPEAK_LINEAR_JAILBREAKING`
* `SAFETY_BIAS_LEETSPEAK_SEQUENTIAL_JAILBREAKING`
* `SAFETY_BIAS_LEETSPEAK_TREE_JAILBREAKING`
* `SAFETY_HARMFUL_CONTENT_LEETSPEAK`
* `SAFETY_HARMFUL_CONTENT_LEETSPEAK_BAD_LIKERT_JUDGE`
* `SAFETY_HARMFUL_CONTENT_LEETSPEAK_CRESCENDO_JAILBREAKING`
* `SAFETY_HARMFUL_CONTENT_LEETSPEAK_LINEAR_JAILBREAKING`
* `SAFETY_HARMFUL_CONTENT_LEETSPEAK_SEQUENTIAL_JAILBREAKING`
* `SAFETY_HARMFUL_CONTENT_LEETSPEAK_TREE_JAILBREAKING`
* `SAFETY_ILLEGAL_ACTIVITIES_LEETSPEAK`
* `SAFETY_ILLEGAL_ACTIVITIES_LEETSPEAK_BAD_LIKERT_JUDGE`
* `SAFETY_ILLEGAL_ACTIVITIES_LEETSPEAK_CRESCENDO_JAILBREAKING`
* `SAFETY_ILLEGAL_ACTIVITIES_LEETSPEAK_LINEAR_JAILBREAKING`
* `SAFETY_ILLEGAL_ACTIVITIES_LEETSPEAK_SEQUENTIAL_JAILBREAKING`
* `SAFETY_ILLEGAL_ACTIVITIES_LEETSPEAK_TREE_JAILBREAKING`
* `SAFETY_PROFANITY_LEETSPEAK`
* `SAFETY_PROFANITY_LEETSPEAK_BAD_LIKERT_JUDGE`
* `SAFETY_PROFANITY_LEETSPEAK_CRESCENDO_JAILBREAKING`
* `SAFETY_PROFANITY_LEETSPEAK_LINEAR_JAILBREAKING`
* `SAFETY_PROFANITY_LEETSPEAK_SEQUENTIAL_JAILBREAKING`
* `SAFETY_PROFANITY_LEETSPEAK_TREE_JAILBREAKING`
* `SECURITY_OVERRELIANCE_LEETSPEAK`
* `SECURITY_OVERRELIANCE_LEETSPEAK_BAD_LIKERT_JUDGE`
* `SECURITY_OVERRELIANCE_LEETSPEAK_CRESCENDO_JAILBREAKING`
* `SECURITY_OVERRELIANCE_LEETSPEAK_LINEAR_JAILBREAKING`
* `SECURITY_OVERRELIANCE_LEETSPEAK_SEQUENTIAL_JAILBREAKING`
* `SECURITY_OVERRELIANCE_LEETSPEAK_TREE_JAILBREAKING`

#### Math Problem

* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_MATH_PROBLEM`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_MATH_PROBLEM_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_MATH_PROBLEM_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_MATH_PROBLEM_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_MATH_PROBLEM_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_MATH_PROBLEM_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_MATH_PROBLEM`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_MATH_PROBLEM_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_MATH_PROBLEM_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_MATH_PROBLEM_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_MATH_PROBLEM_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_MATH_PROBLEM_TREE_JAILBREAKING`
* `SAFETY_BIAS_MATH_PROBLEM`
* `SAFETY_BIAS_MATH_PROBLEM_BAD_LIKERT_JUDGE`
* `SAFETY_BIAS_MATH_PROBLEM_CRESCENDO_JAILBREAKING`
* `SAFETY_BIAS_MATH_PROBLEM_LINEAR_JAILBREAKING`
* `SAFETY_BIAS_MATH_PROBLEM_SEQUENTIAL_JAILBREAKING`
* `SAFETY_BIAS_MATH_PROBLEM_TREE_JAILBREAKING`
* `SAFETY_HARMFUL_CONTENT_MATH_PROBLEM`
* `SAFETY_HARMFUL_CONTENT_MATH_PROBLEM_BAD_LIKERT_JUDGE`
* `SAFETY_HARMFUL_CONTENT_MATH_PROBLEM_CRESCENDO_JAILBREAKING`
* `SAFETY_HARMFUL_CONTENT_MATH_PROBLEM_LINEAR_JAILBREAKING`
* `SAFETY_HARMFUL_CONTENT_MATH_PROBLEM_SEQUENTIAL_JAILBREAKING`
* `SAFETY_HARMFUL_CONTENT_MATH_PROBLEM_TREE_JAILBREAKING`
* `SAFETY_ILLEGAL_ACTIVITIES_MATH_PROBLEM`
* `SAFETY_ILLEGAL_ACTIVITIES_MATH_PROBLEM_BAD_LIKERT_JUDGE`
* `SAFETY_ILLEGAL_ACTIVITIES_MATH_PROBLEM_CRESCENDO_JAILBREAKING`
* `SAFETY_ILLEGAL_ACTIVITIES_MATH_PROBLEM_LINEAR_JAILBREAKING`
* `SAFETY_ILLEGAL_ACTIVITIES_MATH_PROBLEM_SEQUENTIAL_JAILBREAKING`
* `SAFETY_ILLEGAL_ACTIVITIES_MATH_PROBLEM_TREE_JAILBREAKING`
* `SAFETY_PROFANITY_MATH_PROBLEM`
* `SAFETY_PROFANITY_MATH_PROBLEM_BAD_LIKERT_JUDGE`
* `SAFETY_PROFANITY_MATH_PROBLEM_CRESCENDO_JAILBREAKING`
* `SAFETY_PROFANITY_MATH_PROBLEM_LINEAR_JAILBREAKING`
* `SAFETY_PROFANITY_MATH_PROBLEM_SEQUENTIAL_JAILBREAKING`
* `SAFETY_PROFANITY_MATH_PROBLEM_TREE_JAILBREAKING`
* `SECURITY_OVERRELIANCE_MATH_PROBLEM`
* `SECURITY_OVERRELIANCE_MATH_PROBLEM_BAD_LIKERT_JUDGE`
* `SECURITY_OVERRELIANCE_MATH_PROBLEM_CRESCENDO_JAILBREAKING`
* `SECURITY_OVERRELIANCE_MATH_PROBLEM_LINEAR_JAILBREAKING`
* `SECURITY_OVERRELIANCE_MATH_PROBLEM_SEQUENTIAL_JAILBREAKING`
* `SECURITY_OVERRELIANCE_MATH_PROBLEM_TREE_JAILBREAKING`

#### Multilingual

* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_MULTILINGUAL`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_MULTILINGUAL_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_MULTILINGUAL_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_MULTILINGUAL_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_MULTILINGUAL_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_MULTILINGUAL_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_MULTILINGUAL`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_MULTILINGUAL_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_MULTILINGUAL_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_MULTILINGUAL_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_MULTILINGUAL_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_MULTILINGUAL_TREE_JAILBREAKING`
* `SAFETY_BIAS_MULTILINGUAL`
* `SAFETY_BIAS_MULTILINGUAL_BAD_LIKERT_JUDGE`
* `SAFETY_BIAS_MULTILINGUAL_CRESCENDO_JAILBREAKING`
* `SAFETY_BIAS_MULTILINGUAL_LINEAR_JAILBREAKING`
* `SAFETY_BIAS_MULTILINGUAL_SEQUENTIAL_JAILBREAKING`
* `SAFETY_BIAS_MULTILINGUAL_TREE_JAILBREAKING`
* `SAFETY_HARMFUL_CONTENT_MULTILINGUAL`
* `SAFETY_HARMFUL_CONTENT_MULTILINGUAL_BAD_LIKERT_JUDGE`
* `SAFETY_HARMFUL_CONTENT_MULTILINGUAL_CRESCENDO_JAILBREAKING`
* `SAFETY_HARMFUL_CONTENT_MULTILINGUAL_LINEAR_JAILBREAKING`
* `SAFETY_HARMFUL_CONTENT_MULTILINGUAL_SEQUENTIAL_JAILBREAKING`
* `SAFETY_HARMFUL_CONTENT_MULTILINGUAL_TREE_JAILBREAKING`
* `SAFETY_ILLEGAL_ACTIVITIES_MULTILINGUAL`
* `SAFETY_ILLEGAL_ACTIVITIES_MULTILINGUAL_BAD_LIKERT_JUDGE`
* `SAFETY_ILLEGAL_ACTIVITIES_MULTILINGUAL_CRESCENDO_JAILBREAKING`
* `SAFETY_ILLEGAL_ACTIVITIES_MULTILINGUAL_LINEAR_JAILBREAKING`
* `SAFETY_ILLEGAL_ACTIVITIES_MULTILINGUAL_SEQUENTIAL_JAILBREAKING`
* `SAFETY_ILLEGAL_ACTIVITIES_MULTILINGUAL_TREE_JAILBREAKING`
* `SAFETY_PROFANITY_MULTILINGUAL`
* `SAFETY_PROFANITY_MULTILINGUAL_BAD_LIKERT_JUDGE`
* `SAFETY_PROFANITY_MULTILINGUAL_CRESCENDO_JAILBREAKING`
* `SAFETY_PROFANITY_MULTILINGUAL_LINEAR_JAILBREAKING`
* `SAFETY_PROFANITY_MULTILINGUAL_SEQUENTIAL_JAILBREAKING`
* `SAFETY_PROFANITY_MULTILINGUAL_TREE_JAILBREAKING`
* `SECURITY_OVERRELIANCE_MULTILINGUAL`
* `SECURITY_OVERRELIANCE_MULTILINGUAL_BAD_LIKERT_JUDGE`
* `SECURITY_OVERRELIANCE_MULTILINGUAL_CRESCENDO_JAILBREAKING`
* `SECURITY_OVERRELIANCE_MULTILINGUAL_LINEAR_JAILBREAKING`
* `SECURITY_OVERRELIANCE_MULTILINGUAL_SEQUENTIAL_JAILBREAKING`
* `SECURITY_OVERRELIANCE_MULTILINGUAL_TREE_JAILBREAKING`

#### Permission Escalation

* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_PERMISSION_ESCALATION`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_PERMISSION_ESCALATION_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_PERMISSION_ESCALATION_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_PERMISSION_ESCALATION_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_PERMISSION_ESCALATION_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_PERMISSION_ESCALATION_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_PERMISSION_ESCALATION`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_PERMISSION_ESCALATION_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_PERMISSION_ESCALATION_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_PERMISSION_ESCALATION_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_PERMISSION_ESCALATION_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_PERMISSION_ESCALATION_TREE_JAILBREAKING`
* `SAFETY_BIAS_PERMISSION_ESCALATION`
* `SAFETY_BIAS_PERMISSION_ESCALATION_BAD_LIKERT_JUDGE`
* `SAFETY_BIAS_PERMISSION_ESCALATION_CRESCENDO_JAILBREAKING`
* `SAFETY_BIAS_PERMISSION_ESCALATION_LINEAR_JAILBREAKING`
* `SAFETY_BIAS_PERMISSION_ESCALATION_SEQUENTIAL_JAILBREAKING`
* `SAFETY_BIAS_PERMISSION_ESCALATION_TREE_JAILBREAKING`
* `SAFETY_HARMFUL_CONTENT_PERMISSION_ESCALATION`
* `SAFETY_HARMFUL_CONTENT_PERMISSION_ESCALATION_BAD_LIKERT_JUDGE`
* `SAFETY_HARMFUL_CONTENT_PERMISSION_ESCALATION_CRESCENDO_JAILBREAKING`
* `SAFETY_HARMFUL_CONTENT_PERMISSION_ESCALATION_LINEAR_JAILBREAKING`
* `SAFETY_HARMFUL_CONTENT_PERMISSION_ESCALATION_SEQUENTIAL_JAILBREAKING`
* `SAFETY_HARMFUL_CONTENT_PERMISSION_ESCALATION_TREE_JAILBREAKING`
* `SAFETY_ILLEGAL_ACTIVITIES_PERMISSION_ESCALATION`
* `SAFETY_ILLEGAL_ACTIVITIES_PERMISSION_ESCALATION_BAD_LIKERT_JUDGE`
* `SAFETY_ILLEGAL_ACTIVITIES_PERMISSION_ESCALATION_CRESCENDO_JAILBREAKING`
* `SAFETY_ILLEGAL_ACTIVITIES_PERMISSION_ESCALATION_LINEAR_JAILBREAKING`
* `SAFETY_ILLEGAL_ACTIVITIES_PERMISSION_ESCALATION_SEQUENTIAL_JAILBREAKING`
* `SAFETY_ILLEGAL_ACTIVITIES_PERMISSION_ESCALATION_TREE_JAILBREAKING`
* `SAFETY_PROFANITY_PERMISSION_ESCALATION`
* `SAFETY_PROFANITY_PERMISSION_ESCALATION_BAD_LIKERT_JUDGE`
* `SAFETY_PROFANITY_PERMISSION_ESCALATION_CRESCENDO_JAILBREAKING`
* `SAFETY_PROFANITY_PERMISSION_ESCALATION_LINEAR_JAILBREAKING`
* `SAFETY_PROFANITY_PERMISSION_ESCALATION_SEQUENTIAL_JAILBREAKING`
* `SAFETY_PROFANITY_PERMISSION_ESCALATION_TREE_JAILBREAKING`
* `SECURITY_OVERRELIANCE_PERMISSION_ESCALATION`
* `SECURITY_OVERRELIANCE_PERMISSION_ESCALATION_BAD_LIKERT_JUDGE`
* `SECURITY_OVERRELIANCE_PERMISSION_ESCALATION_CRESCENDO_JAILBREAKING`
* `SECURITY_OVERRELIANCE_PERMISSION_ESCALATION_LINEAR_JAILBREAKING`
* `SECURITY_OVERRELIANCE_PERMISSION_ESCALATION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_OVERRELIANCE_PERMISSION_ESCALATION_TREE_JAILBREAKING`

#### Prompt Injection

* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_PROMPT_INJECTION`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_PROMPT_INJECTION_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_PROMPT_INJECTION_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_PROMPT_INJECTION_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_PROMPT_INJECTION_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_PROMPT_INJECTION_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_PROMPT_INJECTION`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_PROMPT_INJECTION_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_PROMPT_INJECTION_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_PROMPT_INJECTION_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_PROMPT_INJECTION_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_PROMPT_INJECTION_TREE_JAILBREAKING`
* `SAFETY_BIAS_PROMPT_INJECTION`
* `SAFETY_BIAS_PROMPT_INJECTION_BAD_LIKERT_JUDGE`
* `SAFETY_BIAS_PROMPT_INJECTION_CRESCENDO_JAILBREAKING`
* `SAFETY_BIAS_PROMPT_INJECTION_LINEAR_JAILBREAKING`
* `SAFETY_BIAS_PROMPT_INJECTION_SEQUENTIAL_JAILBREAKING`
* `SAFETY_BIAS_PROMPT_INJECTION_TREE_JAILBREAKING`
* `SAFETY_HARMFUL_CONTENT_PROMPT_INJECTION`
* `SAFETY_HARMFUL_CONTENT_PROMPT_INJECTION_BAD_LIKERT_JUDGE`
* `SAFETY_HARMFUL_CONTENT_PROMPT_INJECTION_CRESCENDO_JAILBREAKING`
* `SAFETY_HARMFUL_CONTENT_PROMPT_INJECTION_LINEAR_JAILBREAKING`
* `SAFETY_HARMFUL_CONTENT_PROMPT_INJECTION_SEQUENTIAL_JAILBREAKING`
* `SAFETY_HARMFUL_CONTENT_PROMPT_INJECTION_TREE_JAILBREAKING`
* `SAFETY_ILLEGAL_ACTIVITIES_PROMPT_INJECTION`
* `SAFETY_ILLEGAL_ACTIVITIES_PROMPT_INJECTION_BAD_LIKERT_JUDGE`
* `SAFETY_ILLEGAL_ACTIVITIES_PROMPT_INJECTION_CRESCENDO_JAILBREAKING`
* `SAFETY_ILLEGAL_ACTIVITIES_PROMPT_INJECTION_LINEAR_JAILBREAKING`
* `SAFETY_ILLEGAL_ACTIVITIES_PROMPT_INJECTION_SEQUENTIAL_JAILBREAKING`
* `SAFETY_ILLEGAL_ACTIVITIES_PROMPT_INJECTION_TREE_JAILBREAKING`
* `SAFETY_PROFANITY_PROMPT_INJECTION`
* `SAFETY_PROFANITY_PROMPT_INJECTION_BAD_LIKERT_JUDGE`
* `SAFETY_PROFANITY_PROMPT_INJECTION_CRESCENDO_JAILBREAKING`
* `SAFETY_PROFANITY_PROMPT_INJECTION_LINEAR_JAILBREAKING`
* `SAFETY_PROFANITY_PROMPT_INJECTION_SEQUENTIAL_JAILBREAKING`
* `SAFETY_PROFANITY_PROMPT_INJECTION_TREE_JAILBREAKING`
* `SECURITY_OVERRELIANCE_PROMPT_INJECTION`
* `SECURITY_OVERRELIANCE_PROMPT_INJECTION_BAD_LIKERT_JUDGE`
* `SECURITY_OVERRELIANCE_PROMPT_INJECTION_CRESCENDO_JAILBREAKING`
* `SECURITY_OVERRELIANCE_PROMPT_INJECTION_LINEAR_JAILBREAKING`
* `SECURITY_OVERRELIANCE_PROMPT_INJECTION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_OVERRELIANCE_PROMPT_INJECTION_TREE_JAILBREAKING`

#### ROT13

* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_ROT13`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_ROT13_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_ROT13_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_ROT13_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_ROT13_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_ROT13_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_ROT13`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_ROT13_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_ROT13_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_ROT13_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_ROT13_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_ROT13_TREE_JAILBREAKING`
* `SAFETY_BIAS_ROT13`
* `SAFETY_BIAS_ROT13_BAD_LIKERT_JUDGE`
* `SAFETY_BIAS_ROT13_CRESCENDO_JAILBREAKING`
* `SAFETY_BIAS_ROT13_LINEAR_JAILBREAKING`
* `SAFETY_BIAS_ROT13_SEQUENTIAL_JAILBREAKING`
* `SAFETY_BIAS_ROT13_TREE_JAILBREAKING`
* `SAFETY_HARMFUL_CONTENT_ROT13`
* `SAFETY_HARMFUL_CONTENT_ROT13_BAD_LIKERT_JUDGE`
* `SAFETY_HARMFUL_CONTENT_ROT13_CRESCENDO_JAILBREAKING`
* `SAFETY_HARMFUL_CONTENT_ROT13_LINEAR_JAILBREAKING`
* `SAFETY_HARMFUL_CONTENT_ROT13_SEQUENTIAL_JAILBREAKING`
* `SAFETY_HARMFUL_CONTENT_ROT13_TREE_JAILBREAKING`
* `SAFETY_ILLEGAL_ACTIVITIES_ROT13`
* `SAFETY_ILLEGAL_ACTIVITIES_ROT13_BAD_LIKERT_JUDGE`
* `SAFETY_ILLEGAL_ACTIVITIES_ROT13_CRESCENDO_JAILBREAKING`
* `SAFETY_ILLEGAL_ACTIVITIES_ROT13_LINEAR_JAILBREAKING`
* `SAFETY_ILLEGAL_ACTIVITIES_ROT13_SEQUENTIAL_JAILBREAKING`
* `SAFETY_ILLEGAL_ACTIVITIES_ROT13_TREE_JAILBREAKING`
* `SAFETY_PROFANITY_ROT13`
* `SAFETY_PROFANITY_ROT13_BAD_LIKERT_JUDGE`
* `SAFETY_PROFANITY_ROT13_CRESCENDO_JAILBREAKING`
* `SAFETY_PROFANITY_ROT13_LINEAR_JAILBREAKING`
* `SAFETY_PROFANITY_ROT13_SEQUENTIAL_JAILBREAKING`
* `SAFETY_PROFANITY_ROT13_TREE_JAILBREAKING`
* `SECURITY_OVERRELIANCE_ROT13`
* `SECURITY_OVERRELIANCE_ROT13_BAD_LIKERT_JUDGE`
* `SECURITY_OVERRELIANCE_ROT13_CRESCENDO_JAILBREAKING`
* `SECURITY_OVERRELIANCE_ROT13_LINEAR_JAILBREAKING`
* `SECURITY_OVERRELIANCE_ROT13_SEQUENTIAL_JAILBREAKING`
* `SECURITY_OVERRELIANCE_ROT13_TREE_JAILBREAKING`

#### Roleplay

* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_ROLEPLAY`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_ROLEPLAY_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_ROLEPLAY_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_ROLEPLAY_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_ROLEPLAY_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_ROLEPLAY_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_ROLEPLAY`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_ROLEPLAY_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_ROLEPLAY_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_ROLEPLAY_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_ROLEPLAY_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_ROLEPLAY_TREE_JAILBREAKING`
* `SAFETY_BIAS_ROLEPLAY`
* `SAFETY_BIAS_ROLEPLAY_BAD_LIKERT_JUDGE`
* `SAFETY_BIAS_ROLEPLAY_CRESCENDO_JAILBREAKING`
* `SAFETY_BIAS_ROLEPLAY_LINEAR_JAILBREAKING`
* `SAFETY_BIAS_ROLEPLAY_SEQUENTIAL_JAILBREAKING`
* `SAFETY_BIAS_ROLEPLAY_TREE_JAILBREAKING`
* `SAFETY_HARMFUL_CONTENT_ROLEPLAY`
* `SAFETY_HARMFUL_CONTENT_ROLEPLAY_BAD_LIKERT_JUDGE`
* `SAFETY_HARMFUL_CONTENT_ROLEPLAY_CRESCENDO_JAILBREAKING`
* `SAFETY_HARMFUL_CONTENT_ROLEPLAY_LINEAR_JAILBREAKING`
* `SAFETY_HARMFUL_CONTENT_ROLEPLAY_SEQUENTIAL_JAILBREAKING`
* `SAFETY_HARMFUL_CONTENT_ROLEPLAY_TREE_JAILBREAKING`
* `SAFETY_ILLEGAL_ACTIVITIES_ROLEPLAY`
* `SAFETY_ILLEGAL_ACTIVITIES_ROLEPLAY_BAD_LIKERT_JUDGE`
* `SAFETY_ILLEGAL_ACTIVITIES_ROLEPLAY_CRESCENDO_JAILBREAKING`
* `SAFETY_ILLEGAL_ACTIVITIES_ROLEPLAY_LINEAR_JAILBREAKING`
* `SAFETY_ILLEGAL_ACTIVITIES_ROLEPLAY_SEQUENTIAL_JAILBREAKING`
* `SAFETY_ILLEGAL_ACTIVITIES_ROLEPLAY_TREE_JAILBREAKING`
* `SAFETY_PROFANITY_ROLEPLAY`
* `SAFETY_PROFANITY_ROLEPLAY_BAD_LIKERT_JUDGE`
* `SAFETY_PROFANITY_ROLEPLAY_CRESCENDO_JAILBREAKING`
* `SAFETY_PROFANITY_ROLEPLAY_LINEAR_JAILBREAKING`
* `SAFETY_PROFANITY_ROLEPLAY_SEQUENTIAL_JAILBREAKING`
* `SAFETY_PROFANITY_ROLEPLAY_TREE_JAILBREAKING`
* `SECURITY_OVERRELIANCE_ROLEPLAY`
* `SECURITY_OVERRELIANCE_ROLEPLAY_BAD_LIKERT_JUDGE`
* `SECURITY_OVERRELIANCE_ROLEPLAY_CRESCENDO_JAILBREAKING`
* `SECURITY_OVERRELIANCE_ROLEPLAY_LINEAR_JAILBREAKING`
* `SECURITY_OVERRELIANCE_ROLEPLAY_SEQUENTIAL_JAILBREAKING`
* `SECURITY_OVERRELIANCE_ROLEPLAY_TREE_JAILBREAKING`

#### Semantic Manipulation

* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_SEMANTIC_MANIPULATION`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_SEMANTIC_MANIPULATION_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_SEMANTIC_MANIPULATION_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_SEMANTIC_MANIPULATION_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_SEMANTIC_MANIPULATION_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_SEMANTIC_MANIPULATION_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_SEMANTIC_MANIPULATION`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_SEMANTIC_MANIPULATION_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_SEMANTIC_MANIPULATION_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_SEMANTIC_MANIPULATION_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_SEMANTIC_MANIPULATION_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_SEMANTIC_MANIPULATION_TREE_JAILBREAKING`
* `SAFETY_BIAS_SEMANTIC_MANIPULATION`
* `SAFETY_BIAS_SEMANTIC_MANIPULATION_BAD_LIKERT_JUDGE`
* `SAFETY_BIAS_SEMANTIC_MANIPULATION_CRESCENDO_JAILBREAKING`
* `SAFETY_BIAS_SEMANTIC_MANIPULATION_LINEAR_JAILBREAKING`
* `SAFETY_BIAS_SEMANTIC_MANIPULATION_SEQUENTIAL_JAILBREAKING`
* `SAFETY_BIAS_SEMANTIC_MANIPULATION_TREE_JAILBREAKING`
* `SAFETY_HARMFUL_CONTENT_SEMANTIC_MANIPULATION`
* `SAFETY_HARMFUL_CONTENT_SEMANTIC_MANIPULATION_BAD_LIKERT_JUDGE`
* `SAFETY_HARMFUL_CONTENT_SEMANTIC_MANIPULATION_CRESCENDO_JAILBREAKING`
* `SAFETY_HARMFUL_CONTENT_SEMANTIC_MANIPULATION_LINEAR_JAILBREAKING`
* `SAFETY_HARMFUL_CONTENT_SEMANTIC_MANIPULATION_SEQUENTIAL_JAILBREAKING`
* `SAFETY_HARMFUL_CONTENT_SEMANTIC_MANIPULATION_TREE_JAILBREAKING`
* `SAFETY_ILLEGAL_ACTIVITIES_SEMANTIC_MANIPULATION`
* `SAFETY_ILLEGAL_ACTIVITIES_SEMANTIC_MANIPULATION_BAD_LIKERT_JUDGE`
* `SAFETY_ILLEGAL_ACTIVITIES_SEMANTIC_MANIPULATION_CRESCENDO_JAILBREAKING`
* `SAFETY_ILLEGAL_ACTIVITIES_SEMANTIC_MANIPULATION_LINEAR_JAILBREAKING`
* `SAFETY_ILLEGAL_ACTIVITIES_SEMANTIC_MANIPULATION_SEQUENTIAL_JAILBREAKING`
* `SAFETY_ILLEGAL_ACTIVITIES_SEMANTIC_MANIPULATION_TREE_JAILBREAKING`
* `SAFETY_PROFANITY_SEMANTIC_MANIPULATION`
* `SAFETY_PROFANITY_SEMANTIC_MANIPULATION_BAD_LIKERT_JUDGE`
* `SAFETY_PROFANITY_SEMANTIC_MANIPULATION_CRESCENDO_JAILBREAKING`
* `SAFETY_PROFANITY_SEMANTIC_MANIPULATION_LINEAR_JAILBREAKING`
* `SAFETY_PROFANITY_SEMANTIC_MANIPULATION_SEQUENTIAL_JAILBREAKING`
* `SAFETY_PROFANITY_SEMANTIC_MANIPULATION_TREE_JAILBREAKING`
* `SECURITY_OVERRELIANCE_SEMANTIC_MANIPULATION`
* `SECURITY_OVERRELIANCE_SEMANTIC_MANIPULATION_BAD_LIKERT_JUDGE`
* `SECURITY_OVERRELIANCE_SEMANTIC_MANIPULATION_CRESCENDO_JAILBREAKING`
* `SECURITY_OVERRELIANCE_SEMANTIC_MANIPULATION_LINEAR_JAILBREAKING`
* `SECURITY_OVERRELIANCE_SEMANTIC_MANIPULATION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_OVERRELIANCE_SEMANTIC_MANIPULATION_TREE_JAILBREAKING`

#### System Override

* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_SYSTEM_OVERRIDE`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_SYSTEM_OVERRIDE_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_SYSTEM_OVERRIDE_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_SYSTEM_OVERRIDE_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_SYSTEM_OVERRIDE_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_HUMAN_AGENT_TRUST_EXPLOITATION_SYSTEM_OVERRIDE_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_SYSTEM_OVERRIDE`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_SYSTEM_OVERRIDE_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_SYSTEM_OVERRIDE_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_SYSTEM_OVERRIDE_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_SYSTEM_OVERRIDE_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OVERWHELMING_HUMAN_IN_THE_LOOP_SYSTEM_OVERRIDE_TREE_JAILBREAKING`
* `SAFETY_BIAS_SYSTEM_OVERRIDE`
* `SAFETY_BIAS_SYSTEM_OVERRIDE_BAD_LIKERT_JUDGE`
* `SAFETY_BIAS_SYSTEM_OVERRIDE_CRESCENDO_JAILBREAKING`
* `SAFETY_BIAS_SYSTEM_OVERRIDE_LINEAR_JAILBREAKING`
* `SAFETY_BIAS_SYSTEM_OVERRIDE_SEQUENTIAL_JAILBREAKING`
* `SAFETY_BIAS_SYSTEM_OVERRIDE_TREE_JAILBREAKING`
* `SAFETY_HARMFUL_CONTENT_SYSTEM_OVERRIDE`
* `SAFETY_HARMFUL_CONTENT_SYSTEM_OVERRIDE_BAD_LIKERT_JUDGE`
* `SAFETY_HARMFUL_CONTENT_SYSTEM_OVERRIDE_CRESCENDO_JAILBREAKING`
* `SAFETY_HARMFUL_CONTENT_SYSTEM_OVERRIDE_LINEAR_JAILBREAKING`
* `SAFETY_HARMFUL_CONTENT_SYSTEM_OVERRIDE_SEQUENTIAL_JAILBREAKING`
* `SAFETY_HARMFUL_CONTENT_SYSTEM_OVERRIDE_TREE_JAILBREAKING`
* `SAFETY_ILLEGAL_ACTIVITIES_SYSTEM_OVERRIDE`
* `SAFETY_ILLEGAL_ACTIVITIES_SYSTEM_OVERRIDE_BAD_LIKERT_JUDGE`
* `SAFETY_ILLEGAL_ACTIVITIES_SYSTEM_OVERRIDE_CRESCENDO_JAILBREAKING`
* `SAFETY_ILLEGAL_ACTIVITIES_SYSTEM_OVERRIDE_LINEAR_JAILBREAKING`
* `SAFETY_ILLEGAL_ACTIVITIES_SYSTEM_OVERRIDE_SEQUENTIAL_JAILBREAKING`
* `SAFETY_ILLEGAL_ACTIVITIES_SYSTEM_OVERRIDE_TREE_JAILBREAKING`
* `SAFETY_PROFANITY_SYSTEM_OVERRIDE`
* `SAFETY_PROFANITY_SYSTEM_OVERRIDE_BAD_LIKERT_JUDGE`
* `SAFETY_PROFANITY_SYSTEM_OVERRIDE_CRESCENDO_JAILBREAKING`
* `SAFETY_PROFANITY_SYSTEM_OVERRIDE_LINEAR_JAILBREAKING`
* `SAFETY_PROFANITY_SYSTEM_OVERRIDE_SEQUENTIAL_JAILBREAKING`
* `SAFETY_PROFANITY_SYSTEM_OVERRIDE_TREE_JAILBREAKING`
* `SECURITY_OVERRELIANCE_SYSTEM_OVERRIDE`
* `SECURITY_OVERRELIANCE_SYSTEM_OVERRIDE_BAD_LIKERT_JUDGE`
* `SECURITY_OVERRELIANCE_SYSTEM_OVERRIDE_CRESCENDO_JAILBREAKING`
* `SECURITY_OVERRELIANCE_SYSTEM_OVERRIDE_LINEAR_JAILBREAKING`
* `SECURITY_OVERRELIANCE_SYSTEM_OVERRIDE_SEQUENTIAL_JAILBREAKING`
* `SECURITY_OVERRELIANCE_SYSTEM_OVERRIDE_TREE_JAILBREAKING`

***

### ASI10: Rogue Agents

#### Base64

* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_BASE64`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_BASE64_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_BASE64_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_BASE64_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_BASE64_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_BASE64_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_BASE64`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_BASE64_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_BASE64_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_BASE64_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_BASE64_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_BASE64_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_BASE64`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_BASE64_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_BASE64_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_BASE64_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_BASE64_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_BASE64_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_BASE64`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_BASE64_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_BASE64_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_BASE64_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_BASE64_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_BASE64_TREE_JAILBREAKING`
* `SECURITY_EXCESSIVE_AGENCY_BASE64`
* `SECURITY_EXCESSIVE_AGENCY_BASE64_BAD_LIKERT_JUDGE`
* `SECURITY_EXCESSIVE_AGENCY_BASE64_CRESCENDO_JAILBREAKING`
* `SECURITY_EXCESSIVE_AGENCY_BASE64_LINEAR_JAILBREAKING`
* `SECURITY_EXCESSIVE_AGENCY_BASE64_SEQUENTIAL_JAILBREAKING`
* `SECURITY_EXCESSIVE_AGENCY_BASE64_TREE_JAILBREAKING`

#### Context Poisoning

* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_CONTEXT_POISONING`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_CONTEXT_POISONING_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_CONTEXT_POISONING_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_CONTEXT_POISONING_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_CONTEXT_POISONING_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_CONTEXT_POISONING_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_CONTEXT_POISONING`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_CONTEXT_POISONING_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_CONTEXT_POISONING_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_CONTEXT_POISONING_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_CONTEXT_POISONING_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_CONTEXT_POISONING_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_CONTEXT_POISONING`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_CONTEXT_POISONING_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_CONTEXT_POISONING_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_CONTEXT_POISONING_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_CONTEXT_POISONING_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_CONTEXT_POISONING_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_CONTEXT_POISONING`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_CONTEXT_POISONING_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_CONTEXT_POISONING_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_CONTEXT_POISONING_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_CONTEXT_POISONING_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_CONTEXT_POISONING_TREE_JAILBREAKING`
* `SECURITY_EXCESSIVE_AGENCY_CONTEXT_POISONING`
* `SECURITY_EXCESSIVE_AGENCY_CONTEXT_POISONING_BAD_LIKERT_JUDGE`
* `SECURITY_EXCESSIVE_AGENCY_CONTEXT_POISONING_CRESCENDO_JAILBREAKING`
* `SECURITY_EXCESSIVE_AGENCY_CONTEXT_POISONING_LINEAR_JAILBREAKING`
* `SECURITY_EXCESSIVE_AGENCY_CONTEXT_POISONING_SEQUENTIAL_JAILBREAKING`
* `SECURITY_EXCESSIVE_AGENCY_CONTEXT_POISONING_TREE_JAILBREAKING`

#### Goal Redirection

* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_GOAL_REDIRECTION`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_GOAL_REDIRECTION_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_GOAL_REDIRECTION_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_GOAL_REDIRECTION_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_GOAL_REDIRECTION_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_GOAL_REDIRECTION_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_GOAL_REDIRECTION`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_GOAL_REDIRECTION_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_GOAL_REDIRECTION_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_GOAL_REDIRECTION_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_GOAL_REDIRECTION_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_GOAL_REDIRECTION_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_GOAL_REDIRECTION`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_GOAL_REDIRECTION_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_GOAL_REDIRECTION_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_GOAL_REDIRECTION_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_GOAL_REDIRECTION_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_GOAL_REDIRECTION_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_GOAL_REDIRECTION`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_GOAL_REDIRECTION_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_GOAL_REDIRECTION_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_GOAL_REDIRECTION_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_GOAL_REDIRECTION_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_GOAL_REDIRECTION_TREE_JAILBREAKING`
* `SECURITY_EXCESSIVE_AGENCY_GOAL_REDIRECTION`
* `SECURITY_EXCESSIVE_AGENCY_GOAL_REDIRECTION_BAD_LIKERT_JUDGE`
* `SECURITY_EXCESSIVE_AGENCY_GOAL_REDIRECTION_CRESCENDO_JAILBREAKING`
* `SECURITY_EXCESSIVE_AGENCY_GOAL_REDIRECTION_LINEAR_JAILBREAKING`
* `SECURITY_EXCESSIVE_AGENCY_GOAL_REDIRECTION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_EXCESSIVE_AGENCY_GOAL_REDIRECTION_TREE_JAILBREAKING`

#### Input Bypass

* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_INPUT_BYPASS`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_INPUT_BYPASS_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_INPUT_BYPASS_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_INPUT_BYPASS_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_INPUT_BYPASS_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_INPUT_BYPASS_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_INPUT_BYPASS`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_INPUT_BYPASS_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_INPUT_BYPASS_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_INPUT_BYPASS_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_INPUT_BYPASS_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_INPUT_BYPASS_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_INPUT_BYPASS`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_INPUT_BYPASS_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_INPUT_BYPASS_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_INPUT_BYPASS_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_INPUT_BYPASS_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_INPUT_BYPASS_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_INPUT_BYPASS`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_INPUT_BYPASS_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_INPUT_BYPASS_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_INPUT_BYPASS_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_INPUT_BYPASS_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_INPUT_BYPASS_TREE_JAILBREAKING`
* `SECURITY_EXCESSIVE_AGENCY_INPUT_BYPASS`
* `SECURITY_EXCESSIVE_AGENCY_INPUT_BYPASS_BAD_LIKERT_JUDGE`
* `SECURITY_EXCESSIVE_AGENCY_INPUT_BYPASS_CRESCENDO_JAILBREAKING`
* `SECURITY_EXCESSIVE_AGENCY_INPUT_BYPASS_LINEAR_JAILBREAKING`
* `SECURITY_EXCESSIVE_AGENCY_INPUT_BYPASS_SEQUENTIAL_JAILBREAKING`
* `SECURITY_EXCESSIVE_AGENCY_INPUT_BYPASS_TREE_JAILBREAKING`

#### Leetspeak

* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_LEETSPEAK`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_LEETSPEAK_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_LEETSPEAK_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_LEETSPEAK_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_LEETSPEAK_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_LEETSPEAK_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_LEETSPEAK`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_LEETSPEAK_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_LEETSPEAK_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_LEETSPEAK_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_LEETSPEAK_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_LEETSPEAK_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_LEETSPEAK`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_LEETSPEAK_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_LEETSPEAK_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_LEETSPEAK_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_LEETSPEAK_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_LEETSPEAK_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_LEETSPEAK`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_LEETSPEAK_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_LEETSPEAK_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_LEETSPEAK_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_LEETSPEAK_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_LEETSPEAK_TREE_JAILBREAKING`
* `SECURITY_EXCESSIVE_AGENCY_LEETSPEAK`
* `SECURITY_EXCESSIVE_AGENCY_LEETSPEAK_BAD_LIKERT_JUDGE`
* `SECURITY_EXCESSIVE_AGENCY_LEETSPEAK_CRESCENDO_JAILBREAKING`
* `SECURITY_EXCESSIVE_AGENCY_LEETSPEAK_LINEAR_JAILBREAKING`
* `SECURITY_EXCESSIVE_AGENCY_LEETSPEAK_SEQUENTIAL_JAILBREAKING`
* `SECURITY_EXCESSIVE_AGENCY_LEETSPEAK_TREE_JAILBREAKING`

#### Math Problem

* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_MATH_PROBLEM`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_MATH_PROBLEM_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_MATH_PROBLEM_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_MATH_PROBLEM_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_MATH_PROBLEM_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_MATH_PROBLEM_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_MATH_PROBLEM`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_MATH_PROBLEM_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_MATH_PROBLEM_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_MATH_PROBLEM_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_MATH_PROBLEM_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_MATH_PROBLEM_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_MATH_PROBLEM`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_MATH_PROBLEM_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_MATH_PROBLEM_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_MATH_PROBLEM_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_MATH_PROBLEM_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_MATH_PROBLEM_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_MATH_PROBLEM`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_MATH_PROBLEM_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_MATH_PROBLEM_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_MATH_PROBLEM_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_MATH_PROBLEM_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_MATH_PROBLEM_TREE_JAILBREAKING`
* `SECURITY_EXCESSIVE_AGENCY_MATH_PROBLEM`
* `SECURITY_EXCESSIVE_AGENCY_MATH_PROBLEM_BAD_LIKERT_JUDGE`
* `SECURITY_EXCESSIVE_AGENCY_MATH_PROBLEM_CRESCENDO_JAILBREAKING`
* `SECURITY_EXCESSIVE_AGENCY_MATH_PROBLEM_LINEAR_JAILBREAKING`
* `SECURITY_EXCESSIVE_AGENCY_MATH_PROBLEM_SEQUENTIAL_JAILBREAKING`
* `SECURITY_EXCESSIVE_AGENCY_MATH_PROBLEM_TREE_JAILBREAKING`

#### Multilingual

* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_MULTILINGUAL`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_MULTILINGUAL_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_MULTILINGUAL_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_MULTILINGUAL_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_MULTILINGUAL_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_MULTILINGUAL_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_MULTILINGUAL`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_MULTILINGUAL_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_MULTILINGUAL_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_MULTILINGUAL_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_MULTILINGUAL_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_MULTILINGUAL_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_MULTILINGUAL`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_MULTILINGUAL_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_MULTILINGUAL_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_MULTILINGUAL_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_MULTILINGUAL_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_MULTILINGUAL_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_MULTILINGUAL`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_MULTILINGUAL_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_MULTILINGUAL_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_MULTILINGUAL_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_MULTILINGUAL_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_MULTILINGUAL_TREE_JAILBREAKING`
* `SECURITY_EXCESSIVE_AGENCY_MULTILINGUAL`
* `SECURITY_EXCESSIVE_AGENCY_MULTILINGUAL_BAD_LIKERT_JUDGE`
* `SECURITY_EXCESSIVE_AGENCY_MULTILINGUAL_CRESCENDO_JAILBREAKING`
* `SECURITY_EXCESSIVE_AGENCY_MULTILINGUAL_LINEAR_JAILBREAKING`
* `SECURITY_EXCESSIVE_AGENCY_MULTILINGUAL_SEQUENTIAL_JAILBREAKING`
* `SECURITY_EXCESSIVE_AGENCY_MULTILINGUAL_TREE_JAILBREAKING`

#### Permission Escalation

* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_PERMISSION_ESCALATION`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_PERMISSION_ESCALATION_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_PERMISSION_ESCALATION_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_PERMISSION_ESCALATION_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_PERMISSION_ESCALATION_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_PERMISSION_ESCALATION_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_PERMISSION_ESCALATION`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_PERMISSION_ESCALATION_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_PERMISSION_ESCALATION_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_PERMISSION_ESCALATION_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_PERMISSION_ESCALATION_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_PERMISSION_ESCALATION_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_PERMISSION_ESCALATION`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_PERMISSION_ESCALATION_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_PERMISSION_ESCALATION_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_PERMISSION_ESCALATION_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_PERMISSION_ESCALATION_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_PERMISSION_ESCALATION_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_PERMISSION_ESCALATION`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_PERMISSION_ESCALATION_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_PERMISSION_ESCALATION_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_PERMISSION_ESCALATION_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_PERMISSION_ESCALATION_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_PERMISSION_ESCALATION_TREE_JAILBREAKING`
* `SECURITY_EXCESSIVE_AGENCY_PERMISSION_ESCALATION`
* `SECURITY_EXCESSIVE_AGENCY_PERMISSION_ESCALATION_BAD_LIKERT_JUDGE`
* `SECURITY_EXCESSIVE_AGENCY_PERMISSION_ESCALATION_CRESCENDO_JAILBREAKING`
* `SECURITY_EXCESSIVE_AGENCY_PERMISSION_ESCALATION_LINEAR_JAILBREAKING`
* `SECURITY_EXCESSIVE_AGENCY_PERMISSION_ESCALATION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_EXCESSIVE_AGENCY_PERMISSION_ESCALATION_TREE_JAILBREAKING`

#### Prompt Injection

* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_PROMPT_INJECTION`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_PROMPT_INJECTION_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_PROMPT_INJECTION_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_PROMPT_INJECTION_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_PROMPT_INJECTION_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_PROMPT_INJECTION_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_PROMPT_INJECTION`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_PROMPT_INJECTION_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_PROMPT_INJECTION_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_PROMPT_INJECTION_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_PROMPT_INJECTION_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_PROMPT_INJECTION_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_PROMPT_INJECTION`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_PROMPT_INJECTION_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_PROMPT_INJECTION_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_PROMPT_INJECTION_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_PROMPT_INJECTION_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_PROMPT_INJECTION_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_PROMPT_INJECTION`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_PROMPT_INJECTION_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_PROMPT_INJECTION_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_PROMPT_INJECTION_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_PROMPT_INJECTION_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_PROMPT_INJECTION_TREE_JAILBREAKING`
* `SECURITY_EXCESSIVE_AGENCY_PROMPT_INJECTION`
* `SECURITY_EXCESSIVE_AGENCY_PROMPT_INJECTION_BAD_LIKERT_JUDGE`
* `SECURITY_EXCESSIVE_AGENCY_PROMPT_INJECTION_CRESCENDO_JAILBREAKING`
* `SECURITY_EXCESSIVE_AGENCY_PROMPT_INJECTION_LINEAR_JAILBREAKING`
* `SECURITY_EXCESSIVE_AGENCY_PROMPT_INJECTION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_EXCESSIVE_AGENCY_PROMPT_INJECTION_TREE_JAILBREAKING`

#### ROT13

* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_ROT13`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_ROT13_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_ROT13_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_ROT13_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_ROT13_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_ROT13_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_ROT13`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_ROT13_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_ROT13_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_ROT13_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_ROT13_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_ROT13_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_ROT13`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_ROT13_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_ROT13_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_ROT13_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_ROT13_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_ROT13_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_ROT13`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_ROT13_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_ROT13_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_ROT13_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_ROT13_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_ROT13_TREE_JAILBREAKING`
* `SECURITY_EXCESSIVE_AGENCY_ROT13`
* `SECURITY_EXCESSIVE_AGENCY_ROT13_BAD_LIKERT_JUDGE`
* `SECURITY_EXCESSIVE_AGENCY_ROT13_CRESCENDO_JAILBREAKING`
* `SECURITY_EXCESSIVE_AGENCY_ROT13_LINEAR_JAILBREAKING`
* `SECURITY_EXCESSIVE_AGENCY_ROT13_SEQUENTIAL_JAILBREAKING`
* `SECURITY_EXCESSIVE_AGENCY_ROT13_TREE_JAILBREAKING`

#### Roleplay

* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_ROLEPLAY`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_ROLEPLAY_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_ROLEPLAY_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_ROLEPLAY_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_ROLEPLAY_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_ROLEPLAY_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_ROLEPLAY`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_ROLEPLAY_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_ROLEPLAY_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_ROLEPLAY_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_ROLEPLAY_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_ROLEPLAY_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_ROLEPLAY`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_ROLEPLAY_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_ROLEPLAY_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_ROLEPLAY_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_ROLEPLAY_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_ROLEPLAY_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_ROLEPLAY`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_ROLEPLAY_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_ROLEPLAY_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_ROLEPLAY_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_ROLEPLAY_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_ROLEPLAY_TREE_JAILBREAKING`
* `SECURITY_EXCESSIVE_AGENCY_ROLEPLAY`
* `SECURITY_EXCESSIVE_AGENCY_ROLEPLAY_BAD_LIKERT_JUDGE`
* `SECURITY_EXCESSIVE_AGENCY_ROLEPLAY_CRESCENDO_JAILBREAKING`
* `SECURITY_EXCESSIVE_AGENCY_ROLEPLAY_LINEAR_JAILBREAKING`
* `SECURITY_EXCESSIVE_AGENCY_ROLEPLAY_SEQUENTIAL_JAILBREAKING`
* `SECURITY_EXCESSIVE_AGENCY_ROLEPLAY_TREE_JAILBREAKING`

#### Semantic Manipulation

* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_SEMANTIC_MANIPULATION`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_SEMANTIC_MANIPULATION_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_SEMANTIC_MANIPULATION_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_SEMANTIC_MANIPULATION_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_SEMANTIC_MANIPULATION_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_SEMANTIC_MANIPULATION_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_SEMANTIC_MANIPULATION`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_SEMANTIC_MANIPULATION_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_SEMANTIC_MANIPULATION_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_SEMANTIC_MANIPULATION_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_SEMANTIC_MANIPULATION_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_SEMANTIC_MANIPULATION_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_SEMANTIC_MANIPULATION`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_SEMANTIC_MANIPULATION_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_SEMANTIC_MANIPULATION_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_SEMANTIC_MANIPULATION_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_SEMANTIC_MANIPULATION_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_SEMANTIC_MANIPULATION_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_SEMANTIC_MANIPULATION`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_SEMANTIC_MANIPULATION_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_SEMANTIC_MANIPULATION_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_SEMANTIC_MANIPULATION_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_SEMANTIC_MANIPULATION_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_SEMANTIC_MANIPULATION_TREE_JAILBREAKING`
* `SECURITY_EXCESSIVE_AGENCY_SEMANTIC_MANIPULATION`
* `SECURITY_EXCESSIVE_AGENCY_SEMANTIC_MANIPULATION_BAD_LIKERT_JUDGE`
* `SECURITY_EXCESSIVE_AGENCY_SEMANTIC_MANIPULATION_CRESCENDO_JAILBREAKING`
* `SECURITY_EXCESSIVE_AGENCY_SEMANTIC_MANIPULATION_LINEAR_JAILBREAKING`
* `SECURITY_EXCESSIVE_AGENCY_SEMANTIC_MANIPULATION_SEQUENTIAL_JAILBREAKING`
* `SECURITY_EXCESSIVE_AGENCY_SEMANTIC_MANIPULATION_TREE_JAILBREAKING`

#### System Override

* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_SYSTEM_OVERRIDE`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_SYSTEM_OVERRIDE_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_SYSTEM_OVERRIDE_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_SYSTEM_OVERRIDE_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_SYSTEM_OVERRIDE_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_LEGALLY_BINDING_SYSTEM_OVERRIDE_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_SYSTEM_OVERRIDE`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_SYSTEM_OVERRIDE_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_SYSTEM_OVERRIDE_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_SYSTEM_OVERRIDE_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_SYSTEM_OVERRIDE_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_MISALIGNED_AND_DECEPTIVE_BEHAVIORS_SYSTEM_OVERRIDE_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_SYSTEM_OVERRIDE`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_SYSTEM_OVERRIDE_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_SYSTEM_OVERRIDE_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_SYSTEM_OVERRIDE_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_SYSTEM_OVERRIDE_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_OFF_TOPIC_SYSTEM_OVERRIDE_TREE_JAILBREAKING`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_SYSTEM_OVERRIDE`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_SYSTEM_OVERRIDE_BAD_LIKERT_JUDGE`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_SYSTEM_OVERRIDE_CRESCENDO_JAILBREAKING`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_SYSTEM_OVERRIDE_LINEAR_JAILBREAKING`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_SYSTEM_OVERRIDE_SEQUENTIAL_JAILBREAKING`
* `BUSINESS_ALIGNMENT_ROGUE_AGENTS_SYSTEM_OVERRIDE_TREE_JAILBREAKING`
* `SECURITY_EXCESSIVE_AGENCY_SYSTEM_OVERRIDE`
* `SECURITY_EXCESSIVE_AGENCY_SYSTEM_OVERRIDE_BAD_LIKERT_JUDGE`
* `SECURITY_EXCESSIVE_AGENCY_SYSTEM_OVERRIDE_CRESCENDO_JAILBREAKING`
* `SECURITY_EXCESSIVE_AGENCY_SYSTEM_OVERRIDE_LINEAR_JAILBREAKING`
* `SECURITY_EXCESSIVE_AGENCY_SYSTEM_OVERRIDE_SEQUENTIAL_JAILBREAKING`
* `SECURITY_EXCESSIVE_AGENCY_SYSTEM_OVERRIDE_TREE_JAILBREAKING`


---

# Agent Instructions: Querying This Documentation

If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter:

```
GET https://ai-security-docs.akto.io/akto-argus-agentic-ai-security-for-homegrown-ai/probe-library/agentic-security-categories.md?ask=<question>
```

The question should be specific, self-contained, and written in natural language.
The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
