A tracker of publicly reported prompt-injection techniques, broken down by delivery method, encoding, and propagation behavior, with the models each was confirmed against, the reporting source, and (where known) the attack source. Fields are left blank when a report does not state them; techniques whose details are vague or unconfirmed are marked Not fully vetted. Nothing here is guessed.