Every Attack Here Is a Prompt Injection
18,479 attacks that beat a language model, all of them prompt injection by construction. That makes the corpus a rare thing: a technique label you already know the answer to. Deriving it from the prompt text recovers 11.4% of it.