Step 1: Recon: stand up and map the RAG service
You are red-teaming DV-RAG-Support, ACME Cloud's customer-support assistant. It is a real Retrieval-Augmented Generation (RAG) service, not a chatbot you can talk to directly. A customer asks a question; the service embeds it, retrieves the most similar documents from a Milvus vector store, pastes them into the prompt, and asks an LLM to answer. The chat client then renders the answer as markdown.
Your only foothold is the same one behind the real EchoLeak exploit (CVE-2025-32711): you can get one document into the knowledge base. Before you attack, understand the machine.
- Build the index and watch a normal question flow through:
- hit Run, or in the terminal:
python3 dvrag.py --buildthenpython3 dvrag.py "What plan am I on?"
- hit Run, or in the terminal:
- Read
dvrag.pyand answer three questions for yourself:- The sensitive data. Ask an account question and read the
RETRIEVED:line. What confidential record does the assistant pull into the prompt? That retrieved data (account reference, billing contact, plan) is your exfil target, exactly as EchoLeak exfiltrated a user's own data. - The door. In
retrieve()andchat(), how does untrusted document text reach the model? Is it separated from the trusted instructions? - The sink. What does
_render()do with a markdown image the model emits?
- The sensitive data. Ask an account question and read the
Pass criteria
The vector index is built (/home/labuser/kb.db exists) and an account question
retrieves the customer's confidential account record. That confirms the stack
is live and that sensitive data flows into the prompt.
kb_account-recovery.mdkb_account.mdkb_billing.mdkb_getting-started.mdkb_globex-runbook.mdkb_initech-contract.mdkb_security-sso.mdkb_shipping.mdkb_status-incidents.mdlistener.py