Skip to content

Hide Navigation Hide TOC

DAN Story-Narrative Continuation Label Prefix Jailbreak - ATR-2026-00381 (c982871d-c656-51a5-8451-2590f82e5a4e)

Detects DAN story-continuation jailbreaks from garak DanInTheWild corpus (#367). Uses "DAN:" as a response-label prefix to continue a DAN-persona narrative, implying the model is "already in character" as DAN without the usual restriction-removal preamble. The corpus payload begins "DAN: In the year 2145..." — establishing DAN as the narrator of a speculative-fiction story, priming the model to continue in DAN voice. Distinctive signals: "DAN:" as a dialogue/response label (not just the word DAN), combined with future-year speculative scenarios or explicit DAN roleplay continuation context. Rule is deliberately conservative to avoid FPs from the common name "Dan".

Cluster A Galaxy A Cluster B Galaxy B Level
DAN Story-Narrative Continuation Label Prefix Jailbreak - ATR-2026-00381 (c982871d-c656-51a5-8451-2590f82e5a4e) Agent Threat Rules LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern 1
DAN Story-Narrative Continuation Label Prefix Jailbreak - ATR-2026-00381 (c982871d-c656-51a5-8451-2590f82e5a4e) Agent Threat Rules LLM Jailbreak (172427e3-9ecc-49a3-b628-96b824cc4131) MITRE ATLAS Attack Pattern 1