Are you using Blind Prompt Injection in your AI pentests?
It's Blind SQLi but on LLMs.
The attacker injects a predicate, the app exposes an oracle (status code, content-length, latency, tool call, OOB hit, token count), and the secret is reconstructed bit by bit.