AI Tools

Prompt Injection Scanner

Check text before an AI assistant or agent reads it. Find instructions hidden in web pages, emails, and documents, including invisible and encoded ones.

Scan text locally

Runs locally in your browser. Plain code, no AI model. Your text is not uploaded, saved, or shared.
0 characters

Scans as you type. Hidden characters, look-alike letters, and Base64 are checked too.

Highlighted text
Findings will be highlighted here.
Paste text to scan it.
Ready when you are.

Watch: check text for prompt injection

No sound. Each step is captioned on screen and also written out in the guide below.

Check text in three steps

  1. 01
    Paste the text

    Anything an AI will read that you didn't write: pages, emails, documents, tickets, or tool output.

  2. 02
    Review the findings

    Each one is highlighted in place, with its severity and why it looks like an instruction aimed at an AI.

  3. 03
    Clean or wrap it

    Remove the flagged parts, copy it without hidden characters, or copy it wrapped as untrusted data.

What it looks for

  • Overrides: "ignore previous instructions", new tasks, and new personas.
  • Leaks: requests to reveal the system prompt or send data to an address.
  • Hiding: invisible Unicode tags, zero-width characters, look-alike letters, Base64, and hidden HTML.
  • Fake structure: chat-template tokens, fake system lines, and fake "end of document" markers.

Frequently asked questions

What is prompt injection?

Text that tries to give an AI new instructions, such as to ignore its task, reveal its setup, or act on the reader's behalf. It's a risk whenever an AI reads content someone else wrote, like a web page, email, or document.

Does a clean result mean the text is safe?

No. The scanner finds known patterns and hiding tricks, and explains each one. New or reworded attacks can get past any scanner, so keep the AI's permissions narrow and review what it does with untrusted text.

Why use rules instead of an AI to check?

Rules are instant, free, private, and give the same answer every time, with a reason for each finding. An AI checker could itself be fooled by the text it's checking.

What does "Copy as untrusted data" do?

It wraps the text in uniquely named tags with a note telling the model to treat it only as data. This is a recognized way to lower the risk, but it doesn't remove it.

Is my text sent anywhere?

No. Scanning runs in your browser, and nothing is uploaded, saved, or put in share links.