A prompt attack that gets a model to bypass its safety training and produce content it was trained to refuse.