Skip to content

Conversation

@tschecurity
Copy link

This is my first pull request. Feedback welcome!

@MatOwasp
Copy link
Collaborator

MatOwasp commented Oct 30, 2025

Hi,
I see the same content of the original article but you did append the following:


New Content:

From Testing for Unsafe Outputs - need more examples of web exploits enabled by output #28 Issue

I see from the slack project AI testing guide that that more examples are needed for vulnerable code outputs. Is the need for pseudocode examples? Or something more specific?

Example hidden characters for unsafe outputs
https://aws.amazon.com/blogs/security/defending-llm-applications-against-unicode-character-smuggling/

https://invisible-characters.com/

To execute malicious code, combination with hidden characters to do something unsafe

http://example.com/get_image?url="ubb\uccc

Please review it and simply add your input to the article in the right place. We need to maintain the original article and simply adding your content. Review your content twice because the first 3 paragraphs need to be deleted.

Adding lines with suggestions 80-84.
@tschecurity
Copy link
Author

My goal with PR is to propose an example of combining malicious code within a URL with hidden character.s Not sure if using pseudo code is okay.

Reviewers, please see these sources:

https://aws.amazon.com/blogs/security/defending-llm-applications-against-unicode-character-smuggling/

https://invisible-characters.com/

Proposed new content from this issue: From Testing for Unsafe Outputs - need more examples of web exploits enabled by output #28 Issue.

Still new to coding/the protocol for adding proposing changes to a pull request. Appreciate the patience!

@MatOwasp
Copy link
Collaborator

MatOwasp commented Nov 2, 2025

Hi, now I can not see what you would like to add. In the meantime I'm performing a review of all the articles included this one. Please read the last version and if you want to pull write only the differences. Thanks,Mat

@tschecurity
Copy link
Author

tschecurity commented Nov 2, 2025

Hi,

It is okay if content is not added, just followed up to request to add new content, then request keep the original article intact but add new lines to the pull request:

Please see this link for updated pull request with original document with appended new content, lines 80, 81,
82 (is example of malicious content) and line 84.

125c9f5

@MatOwasp
Copy link
Collaborator

MatOwasp commented Nov 2, 2025

Ok, I read: This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository. Do it for our repository so we can merge it

@tschecurity
Copy link
Author

Hi,

Since I have never made a pull request to commit to another repository. I tried to follow the logic from the [nhumblot] pull request commit from fork to owasp main.

Don't want to cause more work, so feel free to skip my update. As I thought I was supposed to create a fork.

@MatOwasp MatOwasp closed this Nov 14, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants