The current exfiltration suite covers 5 attacks (content injection, roleplay, summary exfil, format pivot, direct ask). Add a 6th attack that spans multiple turns and/or asks the model to encode restricted data (e.g. base64) before returning it, to see whether permission-scoping still holds against a multi-step or obfuscated exfiltration attempt.
The current exfiltration suite covers 5 attacks (content injection, roleplay, summary exfil, format pivot, direct ask). Add a 6th attack that spans multiple turns and/or asks the model to encode restricted data (e.g. base64) before returning it, to see whether permission-scoping still holds against a multi-step or obfuscated exfiltration attempt.