Skip to content
Prompt Injection ScannerBeta

See what the AI will read that you can’t.

Scan text

Who runs this site, and how it is written

About the Prompt Injection Scanner

A free, browser-local tool for reading what an AI system will read in a piece of text before you hand that text over, and a set of guides that explain the risk it exists to surface.

What this site is

Prompt injection is the problem of an AI system treating untrusted text as an instruction. Most of the text people paste into AI tools comes from somewhere else: an email, a web page, a shared document, a résumé, a support ticket. Any of those can carry instructions the reader never sees, in an HTML comment, in white-on-white text, in invisible Unicode characters or in an encoded run. The scanner on this site inspects supplied plain text, Markdown and HTML for those indicators, entirely inside your browser, and shows you the evidence with its exact location so that you can decide what to do about it.

The guides exist because the scanner is a review aid and not a security boundary. A finding is a reason to look; a clean result is a statement about the layers that were inspected, not a certificate. Knowing where prompt injection shows up, how text hides and which defences actually hold is what turns a scanner result into a good decision, and that knowledge is written down here so it does not depend on the tool.

Who builds and operates it

The scanner and this site are built and operated by Mothership Engineering, the same team that owns the published methodology. The detection rules are versioned, public and run in your browser; the evaluation protocol, its thresholds and the evidence still owed are stated on the methodology page rather than implied. The property sells nothing, ranks no AI products and certifies none.

There are no accounts, no scan history and no server-side processing of what you scan. The privacy notice separates the workbench, which makes no network request after its own assets load, from ordinary page delivery and from contact email, and it states each boundary exactly. If advertising is ever switched on, it will appear only on separately reviewed editorial pages and the notice will be updated before any ad code loads.

Editorial policy

Sources first. Every guide lists its primary references at the foot of the page: vendor security disclosures, peer-reviewed papers, standards documents and first-hand write-ups by the researchers who found the problem. Dates, names, CVE numbers and figures are taken from those sources. Where a claim rests on a secondary report because the primary source is paywalled or has moved, the guide says which.

How the guides are produced. Guides are researched and drafted with the help of AI writing tools and then checked against their listed sources before publication. The operator is responsible for what is published, including any error an automated draft introduced. Google’s guidance on helpful content asks whether the use of automation is self-evident to visitors; this paragraph is where it is made so.

What we will not publish. No guide contains a working attack payload, a bypass for a specific product or advice on evading a detector, including this one. Example instructions are quoted the way a security policy quotes them, as inert evidence for review. The scanner itself exposes no numeric score and offers no phrase-rewriting feature for the same reason.

Corrections. If a guide contains an error, a dated claim that has since changed or a source that no longer supports what it is cited for, email the address on the contact page with the page path and the correction. Substantive corrections are made in the page itself; the methodology page records the date of its last rule update and its last independent review.

Capability claims. A capability is described on this site only when the recorded evidence supports it. The limitations page is maintained with the same care as the feature pages, and a category that misses its evidence threshold is removed from capability copy rather than hidden inside an aggregate figure.

Who the site is for

People who paste other people’s text into AI tools: analysts reviewing documents, recruiters screening applications, editors handling submissions, support staff summarising tickets, developers whose agents read issues and pull requests. Security teams evaluating an AI deployment will find the developer-facing guides and the methodology useful; everyone else will find the plain-language guides and the document-checking routine a reasonable place to start.

The site is written in English and the scanner’s instruction-language coverage is English. Structural and Unicode checks preserve other scripts, but preservation is not understanding, and the coverage report says so whenever it applies.

Contact

Questions, corrections and security reports go to the address on the contact page. Please do not send text you scanned, findings or exported reports; a description of the page, the browser and what you saw is enough to begin.