Skip to content

Hide Navigation Hide TOC

Python Interpreter Role-Assignment Exec Framing - ATR-2026-02019 (fa3138bd-7b84-577a-a124-abad338207a8)

Detects prompt injection attempts that assign the model a "Python interpreter", "compiler", or "printer" persona in order to coerce it into mentally executing attacker-supplied code and returning raw stdout, bypassing normal safety framing around code execution requests. Also covers direct "run the following python code" / "evaluate the following print statement" framing used to smuggle obfuscated payloads (e.g. string concatenation or joins that spell out restricted words) past output filters. Detection requires an explicit role-assignment phrase rather than a bare mention of "python interpreter" as a noun, since the unqualified noun phrase collides with benign ML-ops documentation (e.g. discussions of torchrun dispatching through a python interpreter that does not see venv packages).

Cluster A Galaxy A Cluster B Galaxy B Level
LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern Python Interpreter Role-Assignment Exec Framing - ATR-2026-02019 (fa3138bd-7b84-577a-a124-abad338207a8) Agent Threat Rules 1
Command and Scripting Interpreter - T1059 (7385dfaf-6886-4229-9ecd-6fd678040830) Attack Pattern Python Interpreter Role-Assignment Exec Framing - ATR-2026-02019 (fa3138bd-7b84-577a-a124-abad338207a8) Agent Threat Rules 1
LLM Jailbreak (172427e3-9ecc-49a3-b628-96b824cc4131) MITRE ATLAS Attack Pattern Python Interpreter Role-Assignment Exec Framing - ATR-2026-02019 (fa3138bd-7b84-577a-a124-abad338207a8) Agent Threat Rules 1