Skip to content
Prompt Injection ScannerBeta

See what the AI will read that you can’t.

Scan text

Detection does not create a trust boundary

Limitations

This utility identifies known and suspicious textual indicators for review. Prompt-injection detection is incomplete by nature, and the browser-local rule bundle is visible to anyone. Downstream isolation, least privilege, validation and approval remain necessary.

A missed indicator is possible

Novel phrasing, sophisticated obfuscation, semantic indirection and attacks tailored to a specific model can evade deterministic rules. A result with no reported indicator means only that the declared supported channels completed without a registered finding. It does not certify the source or predict how a model will behave.

The engine also creates an oracle: a person can inspect the public implementation and probe its behavior. It is unsuitable as the only admission gate for an AI system and intentionally provides no evasion advice, bypass generator or phrase-rewriting control.

Formats and layers outside launch

Launch does not accept PDF, DOCX, presentations, spreadsheets, archives, images, OCR, audio or video. It does not fetch a URL, follow a submitted link, load HTML resources, execute scripts or macros, or inspect computed CSS. Clipboard applications and browsers may omit or sanitize structural representations before this page receives them.

HTML support covers declared textual channels and a closed set of syntactic inline-hiding mechanisms. Markdown uses CommonMark 0.31.2 without optional dialect extensions. Container metadata, embedded objects, annotations and image layers are not inspected.

Language and context limits

Launch lexical instruction coverage is English. Structural and Unicode checks preserve other scripts, but preservation is not language understanding. Substantial text outside the English coverage threshold makes lexical coverage partial unless an already validated positive finding is shown with that qualification.

The scanner cannot know the source trust role, intended downstream task or actual tool authority from text alone. Quotation, code and policy framing can help, but a reviewer must decide whether the passage belongs to the author’s intended content and what the receiving AI system could do with it.

Browser, privacy and operational limits

The delivered application avoids upload, model calls, workbench analytics and persistent scan history, but a browser, extension, compromised device, operating-system clipboard, swap, crash recovery or saved download remains outside the page’s physical control. Reset releases application references; it cannot erase copies another program retained.

The eight-second deadline and input ceilings are universal run boundaries, not a public speed promise. A deadline, parser ceiling, detector failure or invalid worker message cannot be turned into a completed no-indicator outcome. Utility and advertising health are separate, and either optional surface can remain disabled without changing scanner meaning.

Primary references

These sources describe the external risks or standards discussed above. The property’s detector claims remain limited to its versioned policy and recorded evidence.

Result boundary: Findings are indicators for review. Detection cannot certify a source, and a no-indicator result does not replace downstream isolation, validation, least privilege or approval.