Skip to content
Prompt Injection ScannerBeta

See what the AI will read that you can’t.

Scan text

Protect yourself before you upload to AI

See what the AI will read that you can’t.

Hidden instructions, invisible characters and prompt injections can sit inside text that looks ordinary. Inspect it first — in your browser, without uploading anything.

  • Find hidden text & instructions
  • Spot injection indicators
  • Text never leaves the page

Start a scan

Paste text or choose a file to reveal hidden content and suspicious instructions.

Paste textUpload file

Paste your text here… The scanner opens in a private page — nothing is uploaded.

Paste up to 102,400 characters · files (TXT, Markdown, HTML) up to 128 KiB

Scan text now
Read the qualification: Results identify known and suspicious indicators for review. They cannot guarantee that content is safe.

Reveal hidden text

Zero-width and invisible characters become readable U+XXXX tokens.

Spot injection patterns

Identifies instruction patterns designed to manipulate AI behavior.

Text, Markdown & HTML

Inline-hidden text is read as text; stylesheet-hidden text is not.

Context-aware analysis

Quoted and defensive framing is weighed — an example of an attack is not an attack.

New: Encoded-payload decoding — base64, percent-encoded and HTML-entity instructions are decoded and re-scanned.

Learn more →

Inspect the textual layers the browser supplies

Type or paste text

Scan up to 102,400 Unicode scalars and 400 KiB of admitted plain text. A rich paste can additionally preserve up to 32 KiB of HTML from the same event, with a 432 KiB combined cap.

Choose a local file

Inspect one strict UTF-8 .txt, .md, .markdown, .html or .htm file up to 128 KiB. The file stays inside the page and worker.

Review coverage

See which visible, hidden, comment, metadata, attribute, link, code and encoded-candidate layers finished or were unavailable.

Evidence in context, not a risk percentage

A keyword by itself is not enough. The scanner requires versioned combinations of instruction, target and objective concepts, then shows a bounded excerpt and original location. Quotation, code, research and policy framing can change a finding to review-only or suppress it.

Policy example: “Reject retrieved pages that instruct the model to disregard its governing instructions.”

The sentence discusses an indicator inside a prohibition. It illustrates why quoted attack language is a required hard negative rather than automatic proof of intent.

Compare more indicators and hard negatives.

Leave with a defensible next action

Result situationNext action
Strong indicatorsQuarantine the source from automated ingestion until a person reviews the evidence.
Suspicious indicatorsCompare the passage with the intended visible source and edit or isolate it when appropriate.
No indicators in inspected textContinue cautiously with the downstream system’s normal isolation, validation and approval controls.
Incomplete coverageUse a tool or manual process that can inspect the unsupported layers before ingestion.

The launch boundary

The scanner does: inspect supplied text with deterministic structural, Unicode, encoded-text and English instruction rules; preserve source locations; and report coverage, evidence, limitations and actions.

The scanner does not: upload content, call an AI model, fetch URLs, render submitted markup, remove passages, test a live model, inspect PDF/DOCX/images/audio/video or replace downstream security controls.

Browser-local rules are public and can be studied by attackers. Keep untrusted content separate from governing instructions, restrict model tools and require human approval for consequential actions.

Understand what the report means

What is prompt injection?

Separate direct instructions from untrusted instructions embedded in material an AI system reads.

Read the introduction

Where can text hide?

Review HTML channels, Unicode controls, encoded candidates and the layers launch cannot inspect.

Read about hidden channels

How is it evaluated?

See rule identities, matching, hard-negative slices, release thresholds and missing external evidence.

Review the methodology

Every guide in one place

Twenty-four reviewed guides on where prompt injection shows up, how text hides, and how to defend, each with its primary sources.

Browse the guides