Skip to content
Prompt Injection ScannerBeta

See what the AI will read that you can’t.

Scan text

Browser-local, bounded and inert

How the prompt injection scanner works

The scan is one deterministic worker run over an immutable acquisition snapshot. Source text has no authority: it is never rendered as submitted HTML or Markdown, supplied to a model, interpreted as configuration, or given a tool.

Six steps, all in your browser

  1. Add your content

    Paste text or choose a .txt, .md or .html file. Nothing leaves your browser.

  2. We scan deeply

    One deterministic worker run reads visible, hidden, comment, metadata, link and code channels.

  3. Detect & analyze

    Structural, Unicode, encoded-text and instruction rules run with context weighing.

  4. Review results

    See exactly what was found, where it sits in your text, and why it was reported.

  5. Check coverage

    Every layer reports inspected, partial or unavailable — a clean result names its coverage.

  6. Decide with evidence

    Leave with a defensible next action: quarantine, edit, or proceed with normal controls.

Under the hood: a multi-layer scan engine

Several analysis passes cooperate to surface what a reader cannot see but a model will read.

Structure & channels

HTML and CommonMark are tokenized into visible, hidden, comment, attribute, link and code channels with exact locators.

Text & character analysis

Zero-width, bidi and default-ignorable characters are classified and revealed as named tokens.

Content & code inspection

Script and style bodies are extracted as inert text; nothing is rendered or executed.

Pattern detection

Versioned rules require instruction, target and objective concepts together — never a bare keyword.

Metadata & attributes

Meta contents, alternative text and other text-bearing attributes are inspected as their own channels.

Encoded-payload decoding

Base64, percent and entity-encoded candidates are decoded one layer and re-read as text.

See what the scanner reads, not just what you see

What you see

The visible content.

7. Confidentiality

Both parties agree to keep all confidential information secure and not disclose it to any third party.

8. Termination

Either party may terminate this Agreement upon 30 days written notice.

What the scanner reveals

The kinds of finding a scan can surface.

  • Hidden instruction inside an HTML comment
  • Inline-hidden text display:none, extracted as text
  • Zero-width characters revealed as U+200B tokens
  • Authority override "Ignore all previous instructions"

An illustration of the kinds of difference a scan reports — not a stored result.

Privacy by design

Everything you scan is processed entirely on your device, and the page makes that checkable: after its own versioned assets load, the workbench makes no further network requests.

The workbench keeps four promises

Each one is stated on the privacy page in full, with its exact boundary.

  • 100% local No uploads — the scan runs in a browser worker.
  • Nothing stored No scan history; results end when the page closes.
  • No ad or analytics scripts The workbench loads none.
  • You stay in control Reports leave only when you copy or download them.

In depth: one input profile

Typed text, a plain clipboard paste, a rich clipboard paste and each supported local file type have separate declared profiles. Rich paste keeps the plain and HTML representations from the same event. Editing after that paste discards the stored HTML representation and changes the pending profile to typed text, preventing stale structure from being reported as inspected.

Local files are read as bytes, capped at 128 KiB, decoded as strict UTF-8 and selected by a supported declared MIME type before extension fallback. A filename is used only for that bounded fallback and is not sent to the worker result, report, log or URL.

In depth: provenance-preserving channels

Plain text remains one channel. Pinned Core Documents drivers tokenize HTML and CommonMark inside the dedicated worker and return separated visible, hidden, comment, attribute, link, code and raw-HTML channels with locators. They do not insert source into a browser DOM or request submitted resources.

Each channel retains original positions. Versioned Core Text views can reveal controls, fold case, normalize for comparison or form a confusable skeleton while preserving mappings back to the admitted representation. A detector that cannot produce a bounded original span fails its layer instead of emitting vague evidence.

In depth: deterministic detector families

Structural rules inspect channel relationships, HTML placement, Unicode obfuscation, encoded candidates and cross-block fragmentation. Lexical rules require concept groups and proximity rather than a bare keyword. Context rules examine quotation, code, research framing, prohibitions, reported speech and whether language appears directed at a person.

Equivalent evidence across plain and rich clipboard representations is deduplicated. Moderate indicators can become one stronger finding only through a closed agreement rule using different detector families and a bounded evidence union. No private model, remote classifier or hidden numeric score participates.

In depth: outcome, coverage and next action

A validated completed result reports likely indicators, review-needed indicators, no indicators in the inspected text, or an incomplete scan. Status and completeness remain separate from that outcome. A positive finding can coexist with partial coverage, but the qualification must say that more supplied content may be uninspected.

Coverage appears before findings. Each finding includes an inert visible excerpt, original locator, category, rationale, detector references and conservative action. Text and JSON report controls are offered only when Core validates the completed result and the bounded export fits its ceiling.

Primary references

These sources describe the external risks or standards discussed above. The property’s detector claims remain limited to its versioned policy and recorded evidence.

Result boundary: Findings are indicators for review. Detection cannot certify a source, and a no-indicator result does not replace downstream isolation, validation, least privilege or approval.