This is a heavily interactive web application, and JavaScript is required. Simple HTML interfaces are possible, but that is not what this is.
Post
Gerald Benischke
beny23.github.io
did:plc:7pt2bkt6vhlikfbp54ra2jeq
Lovely indirect prompt injection.
Egress protection is hard. I guess this would work with exfiltrating to GitHub too.
https://embracethered.com/blog/posts/2025/claude-abusing-network-access-and-anthropic-api-for-data-exfiltration/
2025-11-01T00:29:45.564Z