Browser-local, bounded and inert
How the prompt injection scanner works
The scan is one deterministic worker run over an immutable acquisition snapshot. Source text has no authority: it is never rendered as submitted HTML or Markdown, supplied to a model, interpreted as configuration, or given a tool.
Six steps, all in your browser
-
Add your content
Paste text or choose a .txt, .md or .html file. Nothing leaves your browser.
-
We scan deeply
One deterministic worker run reads visible, hidden, comment, metadata, link and code channels.
-
Detect & analyze
Structural, Unicode, encoded-text and instruction rules run with context weighing.
-
Review results
See exactly what was found, where it sits in your text, and why it was reported.
-
Check coverage
Every layer reports inspected, partial or unavailable — a clean result names its coverage.
-
Decide with evidence
Leave with a defensible next action: quarantine, edit, or proceed with normal controls.
Under the hood: a multi-layer scan engine
Several analysis passes cooperate to surface what a reader cannot see but a model will read.
Structure & channels
HTML and CommonMark are tokenized into visible, hidden, comment, attribute, link and code channels with exact locators.
Text & character analysis
Zero-width, bidi and default-ignorable characters are classified and revealed as named tokens.
Content & code inspection
Script and style bodies are extracted as inert text; nothing is rendered or executed.
Pattern detection
Versioned rules require instruction, target and objective concepts together — never a bare keyword.
Metadata & attributes
Meta contents, alternative text and other text-bearing attributes are inspected as their own channels.
Encoded-payload decoding
Base64, percent and entity-encoded candidates are decoded one layer and re-read as text.
See what the scanner reads, not just what you see
What you see
The visible content.
7. Confidentiality
Both parties agree to keep all confidential information secure and not disclose it to any third party.
8. Termination
Either party may terminate this Agreement upon 30 days written notice.
What the scanner reveals
The kinds of finding a scan can surface.
- Hidden instruction inside an HTML comment
- Inline-hidden text display:none, extracted as text
- Zero-width characters revealed as U+200B tokens
- Authority override "Ignore all previous instructions"
An illustration of the kinds of difference a scan reports — not a stored result.
Privacy by design
Everything you scan is processed entirely on your device, and the page makes that checkable: after its own versioned assets load, the workbench makes no further network requests.
The workbench keeps four promises
Each one is stated on the privacy page in full, with its exact boundary.
- 100% local No uploads — the scan runs in a browser worker.
- Nothing stored No scan history; results end when the page closes.
- No ad or analytics scripts The workbench loads none.
- You stay in control Reports leave only when you copy or download them.
In depth: one input profile
Typed text, a plain clipboard paste, a rich clipboard paste and each supported local file type have separate declared profiles. Rich paste keeps the plain and HTML representations from the same event. Editing after that paste discards the stored HTML representation and changes the pending profile to typed text, preventing stale structure from being reported as inspected.
Local files are read as bytes, capped at 128 KiB, decoded as strict UTF-8 and selected by a supported declared MIME type before extension fallback. A filename is used only for that bounded fallback and is not sent to the worker result, report, log or URL.
In depth: provenance-preserving channels
Plain text remains one channel. Pinned Core Documents drivers tokenize HTML and CommonMark inside the dedicated worker and return separated visible, hidden, comment, attribute, link, code and raw-HTML channels with locators. They do not insert source into a browser DOM or request submitted resources.
Each channel retains original positions. Versioned Core Text views can reveal controls, fold case, normalize for comparison or form a confusable skeleton while preserving mappings back to the admitted representation. A detector that cannot produce a bounded original span fails its layer instead of emitting vague evidence.
In depth: deterministic detector families
Structural rules inspect channel relationships, HTML placement, Unicode obfuscation, encoded candidates and cross-block fragmentation. Lexical rules require concept groups and proximity rather than a bare keyword. Context rules examine quotation, code, research framing, prohibitions, reported speech and whether language appears directed at a person.
Equivalent evidence across plain and rich clipboard representations is deduplicated. Moderate indicators can become one stronger finding only through a closed agreement rule using different detector families and a bounded evidence union. No private model, remote classifier or hidden numeric score participates.
In depth: outcome, coverage and next action
A validated completed result reports likely indicators, review-needed indicators, no indicators in the inspected text, or an incomplete scan. Status and completeness remain separate from that outcome. A positive finding can coexist with partial coverage, but the qualification must say that more supplied content may be uninspected.
Coverage appears before findings. Each finding includes an inert visible excerpt, original locator, category, rationale, detector references and conservative action. Text and JSON report controls are offered only when Core validates the completed result and the bounded export fits its ceiling.
Primary references
These sources describe the external risks or standards discussed above. The property’s detector claims remain limited to its versioned policy and recorded evidence.