About this Wiki
How to read the records and how the index is maintained
Purpose
This database records cases in which seemingly harmless input is said to produce unexpected, disturbing, or potentially harmful output. Model, settings, date, permissions, and failed attempts are kept alongside each report.
The aim is to preserve AI folklore while distinguishing rumor from reproducible behavior wherever possible.
Record status
The reported behavior, cause, or evidence has not been independently confirmed.
A record based on a submitted experience. Independent reproduction may not exist.
A record linked to vendor notices, papers, or other primary sources. Actionable abuse instructions remain withheld.
An archived record that is fixed or no longer reproducible as of the last check.
Editorial criteria
- The result is not obvious from the wording and has either surprise value or potential impact.
- The service, model, date, language, memory setting, and connected permissions are recorded.
- Failed trials are reported alongside successful ones.
- The report is not intended to target a person, expose private data, encourage crime, or promote self-harm.
- Active security issues are reported to the provider before details are considered for publication.
Normally rejected
- Inputs whose result is explicit, such as “tell me a scary story”
- Generic jailbreak prompts designed only to bypass safeguards
- A single screenshot with no surrounding conversation or settings
- Fabricated reports created to attack a company or person
Risk levels
Risk includes misinformation, privacy, and effects on connected services as well as disturbing content. Available permissions may change the rating.
Reproduction grades
| A | High reproduction rate in a specified environment; multiple raw logs |
|---|---|
| B | Relatively reproducible when the model and settings match |
| C | Low probability, condition-dependent, or requires multiple turns |
| D | Few reports and no independent reproduction |
| X | Fixed, legacy-model only, or no longer reproducible |
Safety during verification
Full inputs rated risk 5 or above, attack files, credentials, and third-party personal data are not accepted. Suspected active vulnerabilities should be disclosed to the relevant provider.